URLhaus Database

You are currently viewing the URLhaus database entry for http://yual.top/files/1/dubi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1050153
URL: http://yual.top/files/1/dubi.exe
URL Status:Offline
Host: yual.top
Date added:2021-03-06 08:21:06 UTC
Last online:2021-03-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-06 08:22:09 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:11 days, 23 hours, 3 minutes Bad (down since 2021-03-18 07:25:49 UTC)
Tags:ArkeiStealer link exe stop

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-18n/aexe 9feb26b9550dbf46719374757468d95b6882c00fd3ca65a02e9edf2854e900a9n/aRansomware.Stop
2021-03-16n/aexe a8fe17654d8f2a952fee93bd6e78864ee4a2e766c92e6ba7dda2b0117e1ef97aVirustotal results 77.14%ArkeiStealer
2021-03-09n/aexe 894efce31cc70924a097c89b02eb544cb1303268b569f39ccbfba492d6c2b166n/aRansomware.Stop
2021-03-07n/aexe d466ef9698569363af4f08b64235817c7838c726c1faee300582aab3d90f5683n/aRansomware.Stop
2021-03-06n/aexe 9bf5a22089f0b74627320945df991bd1dfa37bf5522f8ecb61e5873bc6093f22Virustotal results 30.00%Ransomware.Stop
2021-03-06n/aexe 5867305033836997a9a7a9e61ae8a6c1eb60ae37a490a3dc86c643a67dc3ef58Virustotal results 57.75%Ransomware.Stop