URLhaus Database

You are currently viewing the URLhaus database entry for https://drive.google.com/u/0/uc?id=1XInHLHTgK6ewPK2P8PqTZimphYLtRlmU&export=download which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2707383
URL: https://drive.google.com/u/0/uc?id=1XInHLHTgK6ewPK2P8PqTZimphYLtRlmU&export=download
URL Status:Offline
Host: drive.google.com
Date added:2023-08-26 08:22:05 UTC
Last online:2023-09-30 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-09-30 02:15:07 UTC to network-abuse{at}google[dot]com)
Takedown time:1 month, 6 days, 15 hours, 54 minutes Bad (down since 2023-10-02 00:17:50 UTC)
Tags:bookinggoogledrive MarsStealer pw-4545 Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-28Booking information guest.rarrar 4a553648b4010c59b9306327401e02c4f5b524a3ad8668818a258cb6272ff013n/a 
2023-09-16Booking information guest.rarrar 1c82f4bb418eb316fa151feeba49ee06efafee610c999aefe17a6693b8c90e7cn/a 
2023-09-13Booking information guest.rarrar 62e0c7abc39c2c8a8ab39f7c4a9a2baa43a42da1663d53f8649b612241d0c338n/a 
2023-09-05Booking information guest.rarrar d00412554f3498392bc901df955d91476824f601266f4d31873b3839c2ba5eb0n/a 
2023-09-04Booking information guest.rarrar 4f427fbb941034d86192e7ca200e09ad0e248a87c007cfe82f93c994436c0f37n/a 
2023-09-03Booking information guest.rarrar c0e5980276f9d5e1ae69f03cc8a2b11390a1ea48b75517a2e238deaaba11d7e6n/a 
2023-08-28Booking information guest.rarrar 95dd9dedc46384bb8cd81badc9ddba8c2c7669c7a0727f7b57bc68bbf5237b58n/a 
2023-08-26Booking information guest.rarrar f01a4bf442fac3c6a6c2feab8248b6ba95f3bf0c8d434ce01675454f4d50c79dVirustotal results 0.00%MarsStealer