URLhaus Database

You are currently viewing the URLhaus database entry for http://193.106.191.201/temps/system32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2178064
URL: http://193.106.191.201/temps/system32.exe
URL Status:Offline
Host: 193.106.191.201
Date added:2022-05-04 13:11:04 UTC
Last online:2022-06-27 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-04 13:12:06 UTC to info{at}kanzas[dot]msk[dot]ru)
Takedown time:1 month, 23 days, 21 hours, 32 minutes Bad (down since 2022-06-27 10:44:57 UTC)
Tags:32 ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-23n/aexe 4cf70d18336f6144f709de0f2a4fae8be68fa8e02495af2565c645990c2540f6n/a 
2022-06-15n/aexe 47064b904044944df280dbf24dde946570a381412d55961cdbdd545149c3ffd9n/a 
2022-06-06n/aexe 1c1ce03425793be83b9d250c92531863e1896b40dc2061fe6adbac7fb328c921n/a ArkeiStealer
2022-05-30n/aexe c2a0afb662be00866ddd7a7454e52b5f82252a837121371aa10dd2393d9b1c33n/a ArkeiStealer
2022-05-24n/aexe 36a6921a0de77d733665e1d24cad2e21bede12c5e4495218cd43e66e5b37ce67n/aArkeiStealer
2022-05-17n/aexe 41be5f61865ee6502ddad6af8bdfc5c5c1fe132e555cddd19634fef1c6068dc5n/a ArkeiStealer
2022-05-10n/aexe adc533afdb78f5b2509ce98d5ba8f2fce025675246532a0a0454acf4b02cb640n/aArkeiStealer
2022-05-06n/aexe 9b8ad71c6fb34bcefbe2f3238af93d3f64aa9167904ac0cd639c330e479efe1cn/aArkeiStealer
2022-05-04n/aexe a8cf239166b5764d61fac2971ce6e013a6ee98b3b4af734f13941f2deb1f8ac3Virustotal results 58.82%ArkeiStealer