URLhaus Database

You are currently viewing the URLhaus database entry for https://bluestaks.novationgroups.com/post/Upshotox64.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661730
URL: https://bluestaks.novationgroups.com/post/Upshotox64.exe
URL Status:Offline
Host: bluestaks.novationgroups.com
Date added:2023-06-15 10:33:11 UTC
Last online:2023-06-18 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-06-15 10:34:08 UTC to abuse{at}deft[dot]com)
Takedown time:3 days, 13 hours, 3 minutes Bad (down since 2023-06-18 23:37:55 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-18n/aexe 40cf89b7df3ba8efd66d6f9894a0929b642c6e59ac3fe958ae829729c34004c2n/a 
2023-06-18n/aexe f57b827ade6953b24e048778e9b1e6415d524d410bfc2b4eca39e2fb849df824Virustotal results 26.76% 
2023-06-17n/aexe ab1aeb0415659b9300a49f8ad3162c8193b79759b05c9077ba5e0e9f918c9d7cVirustotal results 18.31% 
2023-06-16n/aexe a6734f7888870bb71002eb528eb1b175b6bcaaf77d216dddd54b13ca967bdfb6Virustotal results 30.99% 
2023-06-15n/aexe 682dc9f1350f3cfab2740e249fc00639927e0a53e8598e07611425dad2821719Virustotal results 42.86%
2023-06-15n/aexe c75bdec56546a04ea55f2c9a987917c01f84bcd82c8ed8250cf430217379a575n/a 
2023-06-15n/aexe 97c71e5a2800a340deda33eab2c85cd7e06201745700fe5add40b84572b0c46cVirustotal results 42.86%