URLhaus Database

You are currently viewing the URLhaus database entry for http://94.130.228.214/umciavi32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2546180
URL: http://94.130.228.214/umciavi32.exe
URL Status:Offline
Host: 94.130.228.214
Date added:2023-02-20 21:31:09 UTC
Last online:2023-03-02 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2023-02-20 21:32:05 UTC to abuse{at}hetzner[dot]com)
Takedown time:10 days, 2 hours, 7 minutes Bad (down since 2023-03-02 23:39:23 UTC)
Tags:Arechclient2 dropped-by-amadey RedLineStealer link rustystealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-01n/aexe 911b862b41c49463c28e91ff8c87aa15057a094cceb98f941af2055ebb85dd39Virustotal results 23.19%ArechClient2
2023-02-25n/aexe bae2374983cd1c5fac119b465091de50292fb2094499a1cf6bc2a7283f7cb7f9n/a 
2023-02-22n/aexe e8e77cc224acb5eeabda000c5aedb207d7c834f6c232aeab3372db9fb858b97an/a RustyStealer
2023-02-20n/aexe 65664a51ce820349f70735c1ec9e5d1134263c911c858308a61aba0c6d8ec227n/aRedLineStealer