URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as CHStealer.

Database Entry


Signature:CHStealer
Firstseen:2025-05-20 02:29:09 UTC
Lastseen:2025-09-26 06:02:04 UTC
Unique Payloads:2
URLs:2

Payload


The table below shows all payloads that have been identified as CHStealer.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-09-26 06:02:04b9a8267d2f1c745f514878ba0b9af016130b82c23437498d24d63b9cf9141ffcExecutable exe5'362'688n/a
2025-05-20 02:29:09fccb531144971b684129a0827c65902334e3e6e30a92f7122c44521e76c82740Executable exe1'049'802Virustotal results 12 / 72 (16.67)

Number of entries displayed: 2 (max: 1'000)