URLhaus Database

You are currently viewing the URLhaus database entry for http://mrfreeman.xyz/nppshell.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2443529
URL: http://mrfreeman.xyz/nppshell.exe
URL Status:Offline
Host: mrfreeman.xyz
Date added:2022-12-04 05:17:10 UTC
Last online:2022-12-06 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-12-04 05:18:05 UTC to abuse{at}dotsi[dot]pt)
Takedown time:2 days, 0 hours, 42 minutes Poor (down since 2022-12-06 06:00:21 UTC)
Tags:32 ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-05n/aexe c2a342f98bacd322a491e70b1fd9210c2c4570e50f403a73dc48a37ae8535685n/a 
2022-12-04n/aexe 8f40998c70d28d552a9683a620fa9cfee1d5067b1a3bd5661b431ebc6e0c7388Virustotal results 1.39% 
2022-12-04n/aexe dc2287e17b52bd031dcafe5287531cdb36ce9ef9416c87b1bb5782f86dc74246Virustotal results 16.67% 
2022-12-04n/aexe 40d0734b985f3b131a175222639d0621b1f7f7a0f90674c676df80191fb215aaVirustotal results 25.35%ArkeiStealer