URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.11/files/7781867830/WkfyDiO.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3347060
URL: http://31.41.244.11/files/7781867830/WkfyDiO.exe
URL Status:Offline
Host: 31.41.244.11
Date added:2024-12-13 02:09:08 UTC
Last online:2024-12-14 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-12-13 02:10:18 UTC to dl{at}redbytes[dot]ru)
Takedown time:1 day, 9 hours, 13 minutes Poor (down since 2024-12-14 11:23:42 UTC)
Tags:GurcuStealer MilleniumRAT MillenuimRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-14n/aexe f4a0b416ca3a94c02563ed3df67d4f8546870662759eb5ae664e6c29a3031afdVirustotal results 26.76%
2024-12-14n/aexe 9d543df8d1d705870da23de3f9a43f467fe998836fd00d7ffff1ea3c4701e5f9n/aGurcuStealer
2024-12-13n/aexe 4413e1c2ded9484071a4cf5b2fbeccea7e617bde8334d58081a8e963b8229361n/a
2024-12-13n/aexe a129d94c366e0caa9a024b5846031b331b5ea7526915299cac3c60c0a79fdde9n/aMilleniumRAT
2024-12-13n/aexe 2a06b6535a0057b961f41e9b0790ffbc6f540566f2c21ae66cee4b61f5a360ebn/aGurcuStealer
2024-12-13n/aexe efd5e8f0852e326a68d4d5cd42d20182ce518fa0b919bb44eeb5450f8830153eVirustotal results 58.33% 
2024-12-13n/aexe 34443c63e5b3678dfd5df2e83fb1c70dcad8fbaa658a25bcde512e216e8d4a1cn/aMillenuimRAT