URLhaus Database

You are currently viewing the URLhaus database entry for http://o3serverfilessl.site/app which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2385448
URL: http://o3serverfilessl.site/app
URL Status:Offline
Host: o3serverfilessl.site
Date added:2022-10-26 06:52:06 UTC
Last online:2022-10-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-26 08:00:14 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:3 hours, 27 minutes Good (down since 2022-10-26 10:20:49 UTC)
Tags:ArkeiStealer link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-26n/aexe e2b95f578e98ccbab8aa058f14fced117303f25997346837f8fa2a71ebc11b96Virustotal results 45.07% ArkeiStealer
2022-10-26n/aexe f0e8c8856176b04515a8003e6830c2a371d52af0b66ebe70232a5fa1afb4a10dVirustotal results 39.44%ArkeiStealer
2022-10-26n/aexe 33b834d43e55548d511dd46076c7ba48db7ffe4a50accc66bd43fa98d6793e41Virustotal results 44.44%ArkeiStealer