URLhaus Database

You are currently viewing the URLhaus database entry for http://andrewjohnson.top/calc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2705935
URL: http://andrewjohnson.top/calc.exe
URL Status:Offline
Host: andrewjohnson.top
Date added:2023-08-21 15:36:06 UTC
Last online:2023-08-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-08-24 09:20:08 UTC to support{at}ruvds[dot]com)
Takedown time:4 days, 4 hours, 38 minutes Bad (down since 2023-08-25 20:15:33 UTC)
Tags:burix dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-25n/aexe 05564e0d6fe1ae0a70943353d51dd0bc19a47ec896ee36533632d34b9f557a90n/aStealc
2023-08-25n/aexe 13ce643b4ba34757d8d5fa9e071308fbb0120bd467588a4b3b7e6181275af6e7n/aStealc
2023-08-25n/aexe 1b0da8603f31103a5d90152c983ddd534e128abed1901fe5debb660c0bb6eccen/aStealc
2023-08-25n/aexe 480afef1f95b2130b1dfceafb7f5639d962c9957e003863dc30f6f7ed40ee79dn/aMarsStealer
2023-08-25n/aexe d8e82dd460b3e9538fcef64e56b5348fa777e5d73dc1d61d92fd49e7e7e7305bn/aStealc
2023-08-24n/aexe 7f175ae66302a4dcf074319d0d89220570a8963d43395d3cf61b3faaab3fe0b1n/a Stealc
2023-08-24n/aexe c4cc355c8e3bc52a53f43f85c606d824b607fd91ffff384393bc7f99823bb219Virustotal results 39.39% Stealc
2023-08-24n/aexe 9e9898215c57e4dd2d5e9e34e6bd3eef1f1594ccb17ef2f1e4c6f90481044a18Virustotal results 43.75% MarsStealer
2023-08-24n/aexe 715821d03d18bb8dab9435aa68a6507532630ed3252dcbf76316a2e8ea228be8Virustotal results 43.08%MarsStealer
2023-08-24n/aexe cc8b9741a463bf30fac6365f6fa6aaf48a63e5a0931bc0eba57cf24f40e7b1bcn/a MarsStealer
2023-08-24n/aexe bff8580b564b68ff541a2f597715b69a2bd9373529eb6278c2e6fcf321fb50bcVirustotal results 42.42% Stealc
2023-08-24n/aexe 6c0089de11a289ffeb0a44db2d5dae12a3684a2f337fd7b49af6e08bb615b76cn/a Stealc
2023-08-24n/aexe c12b55961d4542e07063d063d7f9cc6f5cc6c6b0c388b6565f1bb56fc19662f4n/a MarsStealer
2023-08-23n/aexe 651802363bfec1ee27819b8a7c2b48c68254ba6f75fb48c2b168c779615651f7Virustotal results 44.62%MarsStealer
2023-08-23n/aexe 02b046423b0773b5b5a118ef16da6c55aac47ee3c6d2e861b9a8aaaedc248402Virustotal results 43.94% Stealc
2023-08-23n/aexe cbc45ecc527566af8060f7dbaea341962df2350423dbc3c674c27dcf5b7d3892n/aStealc
2023-08-23n/aexe 2df44897eabeabd3cdcbe54374aa6e29c998e9667090a33a3955c7a803c202a9n/a MarsStealer
2023-08-23n/aexe 0ae1d3ff00b7076d442781a34a881890ff117897c6d889247131eb18f0581f72Virustotal results 42.19%Stealc
2023-08-23n/aexe 01e358f96191d56edb8b11009728fa9ef69ea6628bb86a1c49dfb3122d1a9372n/a MarsStealer
2023-08-23n/aexe 508636b6c60753fad23295328180bf3b2c003437fdabc24a84f6d283fd3d96faVirustotal results 43.66%Stealc
2023-08-23n/aexe d25fce3502958abc307965d62545c45b578a23d7d7878ffcaa0f65ea83068cb3n/aStealc
2023-08-22n/aexe c0d4f11f46c6d39aec1956a0703d1af2f0cfef9becffc8c73be712558dbbdf21Virustotal results 41.79%Stealc
2023-08-22n/aexe e66d15b8ea22a42469fc8f51aee5cb9a5a72360a5a14044fd779182541e419abVirustotal results 41.27% Stealc
2023-08-22n/aexe efe76e209a9575bc73aa11a6c35be706087fdc696645821c5959a4f445540e3dVirustotal results 39.44%Stealc
2023-08-22n/aexe 3a0540a3db9219f4f54fe07ce1777f8c1087b5ed126e5a404935a925e367593cVirustotal results 42.42% MarsStealer
2023-08-22n/aexe 8320b1984cd007f2e819d2572382e0d231feae3b91ec2d30163665aa1295cdc5Virustotal results 40.00%Stealc
2023-08-22n/aexe 7b573396a695127f4df05f183d2efc0e107115a24ccc0458b900e02eaeca2082n/a MarsStealer
2023-08-22n/aexe ee29cc3108d7e380d887d223808f4254eb098bbaffc4639b5988261c8146eb80n/a MarsStealer
2023-08-22n/aexe 8c3379cd31478527d1d0405a836a59220a3cdd3135661b40d30e1ed509c34993n/aStealc
2023-08-22n/aexe 0044ef132e6113d649ef27f1864c350ba16cb7ad5b4257fdb24a8cf9ec670310n/aMarsStealer
2023-08-21n/aexe 151d0f671b56cdeb1f7a2d3cd28160b2e766517fd056e5da4e32110f800a46b9Virustotal results 34.78% MarsStealer
2023-08-21n/aexe 2a8c4927c673ae53fa0b99c0f2e8dce3b09ea7f6ea9855c4140f198b9789f916Virustotal results 39.39%Stealc
2023-08-21n/aexe 34eba2859581b7326e6494e229e992053d0999e074921f95fe55c904efa485ecn/a MarsStealer
2023-08-21n/aexe c0766ce30c875a6a40e50ca428861ce55a6c3133bc8e4f96feabe7de07bb4942n/a MarsStealer
2023-08-21n/aexe ec0583aa7c0fc4ef8363a51b2c56a3ff5b602fa494325525d2a7c27b0775bea8n/a MarsStealer
2023-08-21n/aexe 6321cb7ca4e2ed3b0a5d3472556bfbe959343e0f7a971896189a8a1e7a467370n/aStealc