URLhaus Database

You are currently viewing the URLhaus database entry for http://rgyui.top/dl/build2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2257573
URL: http://rgyui.top/dl/build2.exe
URL Status:Offline
Host: rgyui.top
Date added:2022-07-15 07:52:09 UTC
Last online:2022-10-24 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-24 06:47:09 UTC to registry{at}stc[dot]com[dot]sa)
Takedown time:3 months, 11 days, 1 hours, 38 minutes Bad (down since 2022-10-24 09:31:22 UTC)
Tags:ArkeiStealer link exe geofenced USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-19n/aexe 8ecc0426ea37a5c9e59d00b4fde1508175a950372ec3870965f1e527634b3419Virustotal results 40.28%ArkeiStealer
2022-10-17n/aexe fd5cb18d083e50ca739dff42353802e40acf8ba2694c2a1a2d09a3f40aa7c079n/a 
2022-10-11n/aexe 2a5101345def285c8f52ad39f00261ba9e0375d3de73206d0b8c72ce3b6259c6n/aArkeiStealer
2022-10-03n/aexe 5ee57d85a41b825060864ae85981253f28148d15586a5f6274d562dfeae93e98Virustotal results 38.03%ArkeiStealer
2022-09-27n/aexe 06d1366df3628a010416384f7c77c493ac35f13ee05e010751708d681ebe5169Virustotal results 41.67%ArkeiStealer
2022-09-24n/aexe 6c11af0bbd346329224255d38a07fb9db5828881d3520ab4623c7a5fc09ecd47Virustotal results 76.39%ArkeiStealer
2022-09-14n/aexe 7abb4b2423a93fa4b7a2cd19bcc854cc96d2e9ed20c13b86c39f49fe7cb80e4aVirustotal results 65.71% 
2022-08-24n/aexe a018edd12284d1cdcc235a08ba5da37d3da1d8e886b96c34f1dd8bf7fa41c544Virustotal results 69.01%ArkeiStealer
2022-08-19n/aexe 6f0d21c7e492837cadb64acecb5a714a9290a4f0c522c343d836bfb60114749eVirustotal results 75.36%ArkeiStealer
2022-08-12n/aexe 5cb9acd8876b2341d8df5132ea8b2526111a9b15c020d98204a7c03fc60a7ce0Virustotal results 35.71%ArkeiStealer
2022-08-10n/aexe 14b42331d593ac5ae207f11c6d70d00ac3effbdb1c9eaa9e1dcbd8e4e29a12d6Virustotal results 38.03%ArkeiStealer
2022-08-02n/aexe 12a51367c5c85ff3c1dc73743cface2e01accecf2879a36adbddf566d52987b3Virustotal results 35.82%ArkeiStealer
2022-07-28n/aexe 06f6e14ab8cb8aaacf503675746bf2187bcf967538c9519786a6f2b2ff726b5en/aArkeiStealer
2022-07-19n/aexe a8e37aea3413fb9403e3690b2f1c4edc10b9685de8fda68254c930134e2b2f0fVirustotal results 34.85%ArkeiStealer
2022-07-15n/aexe fd8657ba8b70c80c8aa31de95f01be7fe06e3eb301bcccb2a213b54ba7883b36Virustotal results 55.71%ArkeiStealer