URLhaus Database

You are currently viewing the URLhaus database entry for http://ge-ck365.com/10/data64_1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2286284
URL: http://ge-ck365.com/10/data64_1.exe
URL Status:Offline
Host: ge-ck365.com
Date added:2022-08-31 07:02:06 UTC
Last online:2022-09-27 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-31 07:03:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:27 days, 8 hours, 36 minutes Bad (down since 2022-09-27 15:39:11 UTC)
Tags:ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-10n/aexe 763f2a4d8d484954793cdfeb5c851b3ebce93895b8df57fb91c4082c1928b9b1Virustotal results 36.62% ArkeiStealer
2022-09-05n/aexe 7d2e008bd638b1adde4f0035552e9b85d5c853e72cc0cc54c7d3bb84462481bcVirustotal results 22.54% RedLineStealer
2022-09-04n/aexe 87cbd10a7567f5feb7abc9fea0c7adbf0f2e88be839dce3ebc06d16b66afcf51n/a 
2022-09-04n/aexe 8deb5eeccb0143ed1756e783d1a2401f39a7d8fe9c9c282af31421243432ef9bn/a RedLineStealer
2022-09-03n/aexe 339f383ab12cba709812fa7781afe2b418b4a7ca09ad2a3b6b3ea3388443e93dn/a RedLineStealer
2022-09-02n/aexe 34cdcd0ccda9ba7a51d1f6aaaa8a2a6d6c64f2fb58627a5f0b94d922be6adce1Virustotal results 35.21%RedLineStealer
2022-09-01n/aexe c43c324bb6f807ace828d494d29a2584d95d594ae021a9212a51041d421b2914n/a 
2022-08-31n/aexe d08da5cc4c1d11f130d3771068c52734e85ddec29c481f498f16d6a8ed5c4e95n/aRedLineStealer