URLhaus Database

You are currently viewing the URLhaus database entry for http://thegatehotel.vn/Wechatsextup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1834087
URL: http://thegatehotel.vn/Wechatsextup.exe
URL Status:Offline
Host: thegatehotel.vn
Date added:2021-11-30 00:23:06 UTC
Last online:2021-12-08 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-30 00:24:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 11 hours, 3 minutes Bad (down since 2021-12-08 11:27:48 UTC)
Tags:32 ArkeiStealer link AsyncRAT link exe OskiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-07n/aexe a5f2219b1ca7dfb3a2a049a727dfd2b477982ac2b01071f6e5794a987402a039n/a ArkeiStealer
2021-12-06n/aexe 79f2322a266f7ae7af5686670d8e8bc93661506340aab5e9d63fd23517bbbdd0n/aOskiStealer
2021-12-03n/aexe 7d94781381eabcb7e55417601420ac97ec1b7df80417a1c792aa6135ac42f9b6n/a ArkeiStealer
2021-12-02n/aexe e447edf7c703f03c3644f4d8b896974b7bfa59e7bc4036af5a800c7135dd09b0n/aOskiStealer
2021-12-01n/aexe 6b869d8825516d0b977d48043d1d56d233de7b128074b068566dc33e0ff9fdb7n/aOskiStealer
2021-11-30n/aexe 06d230cca12e200a7b7400e0a6a36fec7811a9d88fadb147fef454c953a23061Virustotal results 60.00%AsyncRAT