URLhaus Database

You are currently viewing the URLhaus database entry for http://dell1.ug/files/cost/5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:225776
URL: http://dell1.ug/files/cost/5.exe
URL Status:Offline
Host: dell1.ug
Date added:2019-08-19 17:23:05 UTC
Last online:2019-10-17 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2019-08-19 17:24:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:1 month, 28 days, 23 hours, 43 minutes Bad (down since 2019-10-17 17:07:19 UTC)
Tags:ArkeiStealer link AZORult link exe Ransomware

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-17n/aexe bdc086c3f0d409a8a9b83c9ebbad68f052c7db0e84d73db7c95dd0851c37e924n/a ArkeiStealer
2019-10-14n/aexe 62be658c4fb2b77315accdc369f1ddc3e652f7f2e54896ee56ebadd0c70bd5a8n/a ArkeiStealer
2019-10-10n/aexe 0d124ae23e139c0eb382c42e128f6fa6f03c681701652f7339e502190a4c1104n/a 
2019-10-10n/aexe 1b77ca2bbacf3d72a1eaaa4b52b38960894fead1101238cd5646193f6bceff45n/a ArkeiStealer
2019-10-10n/aexe 848b8db86046e61b7698a9a035f069926e737db449d170c9ec3ae47658c42d45Virustotal results 68.12% ArkeiStealer
2019-10-03n/aexe 916f809efa29e41a219a89fb5022e0428703bab219bc475f58dd7aa1075ce498n/a ArkeiStealer
2019-10-01n/aexe efc0580aaf81cc77436fd248c4d652261e99c37b14d0870c4f87e0ad0bd1d7a6n/a ArkeiStealer
2019-09-23n/aexe 135d3087600b1b4b3a3589dedf30006d3262de65a5e11fa942df9cb86c04ade2Virustotal results 27.54% ArkeiStealer
2019-09-19n/aexe edd3660918e74f6161f9c4d89419e303940e57b5bdca3a5dbc4795e6059065e4n/a ArkeiStealer
2019-08-19n/aexe e23f2e452ca27e821ed6ce386e1e7d5996be52edc1ce678e80ff2aad0edfb30eVirustotal results 79.66% AZORult