URLhaus Database

You are currently viewing the URLhaus database entry for http://cheapd.link/CALC1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2114262
URL: http://cheapd.link/CALC1.exe
URL Status:Offline
Host: cheapd.link
Date added:2022-03-24 18:51:06 UTC
Last online:2022-03-25 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: benkow_
Abuse complaint sent (?): Yes (2022-03-25 07:14:06 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:21 hours, 18 minutes Good (down since 2022-03-25 16:10:22 UTC)
Tags:ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-25n/aexe c4df33a185795d197ca23e599e8635827ee82800f0736a95e2466e00226cfd7en/a 
2022-03-25n/aexe 88d3c2e14058fe791a3495bef77ce1436ce605c5b63c314944333f20a6f7554fn/a 
2022-03-25n/aexe 6f8d8ef94648300b0ff28111cdb4c1c171738ec06571601d5e9c92a73e4342f2n/a 
2022-03-25n/aexe 12af55a1b76bc59d96116a5f1bc55d3c4ff466f27d3ef2dfce59ff7a14c7e408Virustotal results 38.57% 
2022-03-25n/aexe cca6bea3acf986babf24513880bd4b9f6983d9cd646932140b53483c19756709n/a 
2022-03-25n/aexe c8ad2381228ece7fd82d2fce6cbbf5bfc07167758cb6c55cfd60b3ad6e9005ean/a 
2022-03-25n/aexe 5b65428cd0d750804538847380ce823fe1975121db7250bdb0113194744d0c80Virustotal results 33.82% 
2022-03-25n/aexe 39505867796eee9423b7b258362e09892327a7177eb7651f0ded6f04bb85245fn/a 
2022-03-25n/aexe ff5f03a8c342ea0fc07bedd4affb43af4744a1df3dc5ee3f17a309c78ea6eaaen/a 
2022-03-25n/aexe 9918c9e5a1d65658e8cd25fc29fb1566d9d7cac83cdb9484ecb3548a46ce3b0an/a 
2022-03-25n/aexe 832c70671a8a670679ada1fc611856a1fb0e756ff819cff7c5a3f23e2fa2dc17Virustotal results 35.82% 
2022-03-25n/aexe d7da06ee227da2c3c5fa08cdb674b9b430b6fd84f45bd0bc6e324dad0278888bn/a 
2022-03-25n/aexe 6b560318567d285742c709cfb82b3571c51b15d01d652a8527cb49505e3fad56n/a 
2022-03-25n/aexe ba3fc73699cf76055d2ff71fff603ae83733d17c9c0822ec12d154bb49c88d7bn/a 
2022-03-25n/aexe b21920cc211fa6201f406839d62f10dfc5c81db358960c008a97d8749b31f235n/a 
2022-03-25n/aexe f62d103f9f80c614b1b9fdb823751419146179d30af040eba7f67744fe3fc546n/a 
2022-03-25n/aexe c1d5d69eb1ff280308e0f581e476322cac9b64e745886ad356fd05e843cff342n/a 
2022-03-24n/aexe f116304222910da33ea1591718b51f4def44136626809130ecfe10d82c9c533bn/a 
2022-03-24n/aexe a602b864545539a7981c58a0684e59bd847b9da0e0f5048e03639a419a57e5b9n/a 
2022-03-24n/aexe 267a45c8cdb5296035bcb6433ed981afe34934b30b82c18d5780aeece972b385n/a 
2022-03-24n/aexe 2a13b3b4e815d3856fb26b89dbcfb06a5b025db7f4c0e398ccdbc4477e3d2f58Virustotal results 36.76%ArkeiStealer
2022-03-24n/aexe 573f167f1bdc3b46aad784dd1279d5460857837991fcc1769920c0435a961ef8n/aArkeiStealer
2022-03-24n/aexe 11973b874396eb86766823cf182a40f8ae9e6011e822b64c21e5b13a93922293Virustotal results 35.29%