URLhaus Database

You are currently viewing the URLhaus database entry for https://www.paktravelandtours.com/12/TrdngAnr6339.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2307333
URL: https://www.paktravelandtours.com/12/TrdngAnr6339.exe
URL Status:Offline
Host: www.paktravelandtours.com
Date added:2022-09-19 07:33:08 UTC
Last online:2023-01-03 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-01-03 07:24:05 UTC to abusencc{at}interserver[dot]net)
Takedown time:5 months, 14 days, 5 hours, 15 minutes Bad (down since 2023-03-02 12:49:45 UTC)
Tags:ArkeiStealer link dropby PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-20n/aexe fb76c1cf69ed6a07b60740fc43aed6a49f7a70bd88eeb05befacfd704962ca3dn/a RedLineStealer
2022-09-19n/aexe a5c78d7f77106192a472a71a2136c2f25a9cc5f9a410d16743d6a3e7d8b0757cn/a
2022-09-19n/aexe 144c0fcf6f803810d13f85bb4541c9916eb80e0d0d59bd24e03b5dd9159710dfn/aArkeiStealer