URLhaus Database

You are currently viewing the URLhaus database entry for http://guluiiiimnstrannaer.net/dl/osX66FVEOAQt.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2303569
URL: http://guluiiiimnstrannaer.net/dl/osX66FVEOAQt.exe
URL Status:Offline
Host: guluiiiimnstrannaer.net
Date added:2022-09-15 12:50:06 UTC
Last online:2022-12-17 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-09-15 12:51:11 UTC to info{at}kanzas[dot]msk[dot]ru)
Takedown time:3 months, 3 days, 7 hours, 9 minutes Bad (down since 2022-12-17 20:00:24 UTC)
Tags:ArkeiStealer link exe Smoke Loader link teambot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-15n/aexe f2fa3de8bcd6c2fa66234452611f328be8b25553a4094cac01ee06266a1d907en/a TeamBot
2022-09-15n/aexe fb7fa0ebe5777840b240b67f182b5e6272a6e2853964ef785ad30689901c4c87n/aArkeiStealer
2022-09-15n/aexe ae2aaa44d681f1eb05d76ac0131c2b4bc909b476d5f1d3fb1a44108fc2e016deVirustotal results 36.62%Smoke Loader
2022-09-15n/aexe c4d870915e97ad8901cdb92a27efaa72555bd1567c065c7885ee0a4b8ab1e65dn/aArkeiStealer