URLhaus Database

You are currently viewing the URLhaus database entry for http://bobstayget.top/calc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2689718
URL: http://bobstayget.top/calc.exe
URL Status:Offline
Host: bobstayget.top
Date added:2023-07-25 14:28:07 UTC
Last online:2023-08-01 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-08-01 08:24:07 UTC to hostmaster{at}network-management[dot]net)
Takedown time:20 days, 19 hours, 29 minutes Bad (down since 2023-08-15 09:58:52 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-28n/aexe c473c2b262777f669a99d0a348c82d1a03f7a05d748e57060d011cdeae754c7bn/aMarsStealer
2023-07-28n/aexe 5d4818b6561fc2d1d82eaced028c486905b63229a5af05c27d0271e30957c566n/a MarsStealer
2023-07-28n/aexe 8c7963e14cfd57c416566754ec18aa2e52e9f17ba1a2c75b2707fc36a5aacec4n/a Stealc
2023-07-28n/aexe efa3ca849be8ca58e75dc15509532f18ffddef1db57d06bacf8151f78d3366fbn/a Stealc
2023-07-28n/aexe e9afe6018c84b1f0a4ac4f10fdc6792d77231565354f10bdba22a9f3c84e4a8dn/a Stealc
2023-07-28n/aexe 51f40b9768800c73df2a7c442f79a7598e0c81a41364dc8f10d4797a2965c361n/a MarsStealer
2023-07-28n/aexe e23195cd9b115c6915b05ee67deb33491c1a6966a2f8dcef6d9858578b0862f0n/a Stealc
2023-07-28n/aexe 9f2e5a5c3698774977fc4a5f8481849d0b98c32550176ef343f27891488ba6f7n/a Stealc
2023-07-28n/aexe 0b223ca630759a3ece26f588ce4649816a64c46f4cceecf999abe9a7db50c0d5n/a Stealc
2023-07-28n/aexe 2bda26ee622664a3bac129d374834c9322acb12b4925530416d1c87c9d32b6a3n/a MarsStealer
2023-07-28n/aexe 72281fb9ff28d8c21df7503dff1cbb6f79684cf03c759371135356d6f1e2513cn/a MarsStealer
2023-07-28n/aexe e9b384736a5c030a77a92078822121eccaa4042d756cfaff989e7a486e0ec375n/aMarsStealer
2023-07-28n/aexe 24522c085bebb45e123704c16949e1c450acd159c91b67db7d60cb3e865c2252n/aStealc
2023-07-26n/aexe 020fd62d72e2fc52bd24929f59613f75ea345b8062c7afbd8cdc6d55243d7839n/aMarsStealer
2023-07-26n/aexe 08e063b7a0c135f5df7910c9a18b21de53e72ad9ade8e9d72e14a6e933f27634n/aStealc
2023-07-26n/aexe 75af3d4edfe4996e7690832f25b278021f7dae0a328aa110b86d74820377b054n/aStealc
2023-07-26n/aexe c67307536a1c02ad2fbcebbbed6489a8b70a7cffa9db5b5a98f7409d7732343dn/a MarsStealer
2023-07-26n/aexe 8afd72197f13d7016291b5799cb9e680146d09b9b06661bb0de3f7972ef56fdcn/aStealc
2023-07-26n/aexe b10267a53b79197f53ab91fe82aa53998467f09eef93398c9b48605bd2949e79n/a MarsStealer
2023-07-26n/aexe 772c0f60cb85dc215c7b3fbebea2201eaa8df741d972cd8252cc3e7c1fe79e64n/a MarsStealer
2023-07-26n/aexe 970a7ff3bab4b5fffe226cf5e66d997c9a8692623c2fa17fb5e2d35b16686564n/aMarsStealer
2023-07-26n/aexe ea73f0c424fb7780689b5d0b88bcef9af3b80ed701250ebf8c794b89aea182a4n/aStealc
2023-07-26n/aexe 90281bc45013c23a0ac60de26a46ab84dd9ccb6930a29a6f5c81004093908734n/aStealc
2023-07-25n/aexe 5a18cd3d6cb8563c29b68b71d892d90945bac08b3e5c79a4597e98b40d7720f8n/aStealc
2023-07-25n/aexe 180bb4e28a2faaf8faee1afd083ddfb01782420a1a72a6545a93ec5487b58c78n/aStealc
2023-07-25n/aexe 39e419e214eb8eaec3044defec6894257fc814681c4239e9831bf8458c33b7a9n/aStealc
2023-07-25n/aexe d5b4716082c735fbf29d7984ff7a99d1a5b35fb8071b94223cb34d9d77199a74Virustotal results 38.03%Stealc
2023-07-25n/aexe fd41ab5fa1562ff06b5a81eace78e7e493e3320b4684e218abf8a47a798e684bn/aMarsStealer