URLhaus Database

You are currently viewing the URLhaus database entry for http://load2up.top/setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2629958
URL: http://load2up.top/setup.exe
URL Status:Offline
Host: load2up.top
Date added:2023-05-11 14:59:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-05-18 16:51:07 UTC to noc{at}huize[dot]asia,support{at}62yun[dot]com)
Takedown time:7 days, 10 hours, 31 minutes Bad (down since 2023-05-19 01:32:09 UTC)
Tags:ArkeiStealer link dropped-by-PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-16n/aexe 78a82181988a561b11353f24e1c3f1e2792f4c39db5931baf020318626f04f9eVirustotal results 39.44% RedLineStealer
2023-05-15n/aexe d5753dabf4ad1811f657440d47a810f82eb60c389da494fc4f8b4e43f050842cVirustotal results 33.80% ArkeiStealer
2023-05-14n/aexe f4bbd30a9f0dd272b7810abb9e9a96bb8d0a7cc49c8a4b1723806230614d3e52Virustotal results 46.48% ArkeiStealer
2023-05-11n/aexe 0f99eef3431f8f04eef23ccab335afcd7129e1ca69728ba2bfc929de3010e402n/aArkeiStealer
2023-05-11n/aexe 03042961ebc91064d7e9da04ba292158b34656bf7a05bc868c8f478efa0247dfVirustotal results 50.00%RedLineStealer