URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.88/lend/meta1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2516214
URL: http://62.204.41.88/lend/meta1.exe
URL Status:Offline
Host: 62.204.41.88
Date added:2023-01-23 15:11:11 UTC
Last online:2023-03-27 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-23 15:12:05 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:2 months, 3 days, 0 hours, 44 minutes Bad (down since 2023-03-27 15:56:52 UTC)
Tags:Amadey ArkeiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-19n/aexe 6ee047cd2309e4f3432c8d401928dee739060fa80830331d3c50830fe2653d95n/a
2023-03-14n/aexe 0aafec9ad5c075c5a9dedc18a7e601c0420f9eba92203e3df1bd790a0e7a80b6n/a 
2023-03-05n/aexe fe064ace58872c32f5d656dda082cd40131b6dc82146f6fc85e10b90895bf204n/a
2023-02-06n/aexe 8316a57a9d9234ab3bd9e9626c0eebb5c7a708e2800aecb0713ac452e22c9ec1n/a
2023-02-03n/aexe 9b3a50dc10eb0e67144d29b43b6be6ef932b4d3486659e5c699e72a82b063dd9Virustotal results 60.00% Amadey
2023-01-23n/aexe ac36e4bd21762b111edf4758873dfb1697462e7b08f19f27c0b43fb1186a93d1Virustotal results 30.00%ArkeiStealer