URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as AuraStealer.

Database Entry


Signature:AuraStealer
Firstseen:2025-12-26 16:57:07 UTC
Lastseen:2026-01-24 22:26:14 UTC
Unique Payloads:3
URLs:3

Payload


The table below shows all payloads that have been identified as AuraStealer.

Firstseen (UTC)SHA256File TypeFile sizeVT
2026-01-24 22:26:146b72702b29d1ca3b3bb7b65e58e210fa8bae247d791cf98d09d1ee2930397198Executable exe5'049'344n/a
2025-12-31 01:46:06b39c38d71f2e15e79f9861499379d8e4a2a4b4247fb425630838311e5bc8336aExecutable exe1'635'840n/a
2025-12-26 16:57:07495206892aea114014cfba8c9f605ad9ab6de309a685a59b36d77565919de2e2Executable exe1'635'840n/a

Number of entries displayed: 3 (max: 1'000)