NEW | Hunt across all abuse.ch platforms with one simple query - discover if an IPv4 address, domain, URL or file hash has been identified on any platform from a centralized search tool. Test it out here hunting.abuse.ch - and happy hunting 🔍

URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as DeerStealer.

Database Entry


Signature:DeerStealer
Firstseen:2025-06-06 14:00:09 UTC
Lastseen:2025-06-21 10:59:39 UTC
Unique Payloads:4
URLs:1

Payload


The table below shows all payloads that have been identified as DeerStealer.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-06-21 10:59:3960a7ba37ebffb23c49f1dcb2897fbd3b58f7de2692a068866d1d68c3489789daExecutable exe2'426'880Virustotal results 31 / 72 (43.06)
2025-06-17 17:16:57d8d487fdb3efe93da96a48c48667dc82d0d95c9f6622650ceef99ef1f7a418fcExecutable exe2'452'480Virustotal results 29 / 72 (40.28)
2025-06-09 09:32:1758a5e3bb70bcb50147587807794bcee8ee3c7e5c67a630b092e7899d2a50c83bExecutable exe7'971'141Virustotal results 9 / 72 (12.50)
2025-06-06 14:00:09735b083e68d437acbaa085cab0ad423f1b065497dfdce48acf9320eeeb2e14f4Executable exe2'398'720Virustotal results 28 / 71 (39.44)

Number of entries displayed: 4 (max: 1'000)