URLhaus Database

You are currently viewing the URLhaus database entry for http://nuinew2s.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676964
URL: http://nuinew2s.top/build.exe
URL Status:Offline
Host: nuinew2s.top
Date added:2023-07-05 10:07:07 UTC
Last online:2023-07-07 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: crep1x
Abuse complaint sent (?): Yes (2023-07-05 10:08:06 UTC to info{at}invs[dot]ru)
Takedown time:1 day, 22 hours, 14 minutes Poor (down since 2023-07-07 08:22:20 UTC)
Tags:ArkeiStealer link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-06n/aexe 4c4e0fa35a2a634ad8c070f7ffe6f79f62ac9d12af74231797b68ece3e2cf1a1n/a ArkeiStealer
2023-07-06n/aexe 814d9239d1e5c3d3a4fe46efdbbfb9a43750c7d85f817e555adbaeeba5bcc701n/a ArkeiStealer
2023-07-06n/aexe 64e58df09b422e05e45e27b0105d1142b712a0b06e3efc6cf78ec20b0a274978n/a ArkeiStealer
2023-07-05n/aexe 066fdbbecdb4c5c5bcea1c9c8e817ed2f2883c5f7e184444a95f6a82391a996bn/a ArkeiStealer
2023-07-05n/aexe 1c69a1876b32560d1fec8d4b7f2ecac80f9d85a268b98d1d5d5cac06f48c4aafVirustotal results 45.07%ArkeiStealer
2023-07-05n/aexe cc4fe2e3e3e91e0eaea7673afe3849e0f98d820742f790cccd6d7aacf2f07007Virustotal results 46.48%Lobshot