URLhaus Database

You are currently viewing the URLhaus database entry for http://45.138.74.59/i.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2389317
URL: http://45.138.74.59/i.exe
URL Status:Offline
Host: 45.138.74.59
Date added:2022-10-28 06:18:05 UTC
Last online:2022-10-28 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-28 06:19:10 UTC to abuse{at}aeza[dot]net)
Takedown time:9 hours, 5 minutes Good (down since 2022-10-28 15:24:13 UTC)
Tags:ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-28n/aexe a5a283967a61f5b1a787d072c5946244eac4c3b52165af01a7a099eaa58b0943n/aArkeiStealer
2022-10-28n/aexe 9edf684165900cda2567c388a5ec574bbc6b2c27415cc56e965d5562c4ad1176n/aArkeiStealer
2022-10-28n/aexe 56362cdfd0e92466e0531af9298b4efc0f2a2b4faa3352f41c3c77cf98cde54an/aArkeiStealer
2022-10-28n/aexe a3de421738e83375acc02ad9df1f02ee17077e773409175fdb646a5533e210c2n/aArkeiStealer
2022-10-28n/aexe ac4bd1987b6a72732c2590c7a44f63f63bfa7617ef7f86d8975175b67db4fb30Virustotal results 34.72%ArkeiStealer
2022-10-28n/aexe 02f44f1826304f79afc04b8e3271530d799d8d805ea0501620152d7a1c70a502n/aArkeiStealer
2022-10-28n/aexe a2cd337c4aae8faa1c05d1a756d1e16c27b47f6939fca986d3de493ad792c842n/aArkeiStealer
2022-10-28n/aexe b40106ff8758aafebd4a521af40467b1693537bce239bea4b07deac8ea925f93Virustotal results 36.11%ArkeiStealer
2022-10-28n/aexe cab73be3e1fcca42f723d90cc793d60e3f8029b480554e4dd255de2b1107590fn/aArkeiStealer