URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.12/files/6386900832/9feskIx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3346507
URL: http://31.41.244.12/files/6386900832/9feskIx.exe
URL Status:Offline
Host: 31.41.244.12
Date added:2024-12-12 15:34:01 UTC
Last online:2024-12-14 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-12 15:34:18 UTC to dl{at}redbytes[dot]ru)
Takedown time:1 day, 8 hours, 54 minutes Poor (down since 2024-12-14 00:28:29 UTC)
Tags:AsyncRAT link umbralstealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-13n/aexe 666d91620d589b16b55f847c0c84396419461844d9ab844ad39a7df9d88c34e5Virustotal results 31.43%UmbralStealer
2024-12-12n/aexe 5e5b808ed64c4f40e07a4894e1da294e364383f0a51adb7ec8c7568afba3eb17Virustotal results 35.21%AsyncRAT