URLhaus Database

You are currently viewing the URLhaus database entry for http://171.22.30.106/library.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2305341
URL: http://171.22.30.106/library.php
URL Status:Offline
Host: 171.22.30.106
Date added:2022-09-16 15:51:33 UTC
Last online:2022-09-17 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-09-16 15:52:07 UTC to ripe{at}mayak[dot]bg)
Takedown time:15 hours, 20 minutes Good (down since 2022-09-17 07:12:52 UTC)
Tags:ArkeiStealer link cryptbot RaccoonStealer link RecordBreaker link RedLineStealer link stop ua-2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-16HBMIX.fileexe 549a966a1d755c4b455b57a866179431e775ea4777af0a42d06481967ba5c922Virustotal results 30.00%ArkeiStealer
2022-09-16D4.fileexe 74da82468886e1fe5d3d2fd98035e69ec9b2ac77f48bd42b48f5f20f016703a8Virustotal results 51.47% RaccoonStealer
2022-09-16D3.fileexe 6ff2318912c569e33755a075f32491a9691a8dbcee404b0e5f8ea04910917e94n/aCryptBot
2022-09-16MIXTWO.fileexe 8698f5932bc1b73e3f18770302ce0e64a6d90315e0d49b9c9912a1a027c69b23n/aRedLineStealer
2022-09-16MIXTWO.fileexe 006c93dbcc3938755328928bf3d8e94684de290fe3bf0cbfacdf0448ed0b96edVirustotal results 67.61%RecordBreaker
2022-09-16SBMIX.fileexe 4373427406c989662662b6c706e67f36266fa5a3c903b1ef33512091459501abVirustotal results 62.86% Ransomware.Stop