URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as WraithBot.

Database Entry


Signature:WraithBot
Firstseen:2025-11-03 13:04:06 UTC
Lastseen:2026-01-18 17:42:07 UTC
Unique Payloads:5
URLs:5

Payload


The table below shows all payloads that have been identified as WraithBot.

Firstseen (UTC)SHA256File TypeFile sizeVT
2026-01-18 17:42:07da78dabde4e3b5e0bc94dd69f4f659b3e3890b315f394bc2da2506b84df1c8b0Executable exe539'136n/a
2025-12-10 21:46:125da36b89427b237eaf57d03e7f9a4bbcf3fb34f60efcca9dabf8c20bcf7633e9Executable exe124'928Virustotal results 24 / 71 (33.80)
2025-12-03 22:49:06727ef8598990483205600a38a67ccebea5d9926b9f8312fffaf4e72c6990a933Executable exe131'072n/a
2025-11-30 05:47:08ce7c6f882a0d99b74ba757e9f0634a2fb39cc9bb139d6aafb57ad9572c2de087Executable exe389'632n/a
2025-11-03 13:04:061caa59fa8144591a426aa22bae74def6252a0ae02fef2d340cc742ae30f526f2Executable exe280'576n/a

Number of entries displayed: 5 (max: 1'000)