URLhaus Database

You are currently viewing the URLhaus database entry for http://95.217.43.206/~globaltiam/js/star.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1709504
URL: http://95.217.43.206/~globaltiam/js/star.exe
URL Status:Offline
Host: 95.217.43.206
Date added:2021-10-22 21:23:04 UTC
Last online:2021-12-07 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-07 07:40:34 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 month, 15 days, 16 hours, 6 minutes Bad (down since 2021-12-07 13:30:11 UTC)
Tags:32 exe Globeimposter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-06n/aexe 136f37bb67d7031f5c54ae7d82f7f4e05573b3c6e5d062861c3fd3ee75911352n/a Ransomware.GlobeImposter
2021-12-06n/aexe aa48664b9dea388b3d4abfbeb586e2eb3b7c160c452754942d78030949cbaad3n/a 
2021-12-06n/aexe 03614d528809171ea45459ac44783c841827e663322e3fdfe5b3e2477d47a160n/a
2021-12-05n/aexe 6884fa613525c3d557cffef160c272b7479656b6d34ef00a527504758274ccaan/aRansomware.GlobeImposter
2021-12-04n/aexe 968d19014c65fb18802e4352edaba4f4d0ec9923c4c6c236372bab4ba7e17625n/a Ransomware.GlobeImposter
2021-12-04n/aexe e87701bb299aa9d86fe627745df7aacf19dde67947db647401bafbec457ef196n/a Ransomware.GlobeImposter
2021-12-04n/aexe 21766e51afd193a59b8b32f38d7f852022ee58348537be2fa7620773df237f77n/aRansomware.GlobeImposter
2021-12-03n/aexe 80dd369e6e04d0336831e7b2b9f98abfaf731881d19bb2174ca3891917281731n/a Ransomware.GlobeImposter
2021-12-02n/aexe fcb57e52cb03173f892e418b6876ce536543210d31d83eb7925edf2ca4705f5fn/a Ransomware.GlobeImposter
2021-10-23n/aexe 9add64c3f617392ec57bb083513237bdb50113bf908883aaa40894d6499ba8dbVirustotal results 13.24% 
2021-10-22n/aexe fc8c983c70303955fbbf53be566a1e573a231e2d38aaeaee4ed30a064a1bf172Virustotal results 30.43%