URLhaus Database

You are currently viewing the URLhaus database entry for http://h170578.srv22.test-hf.su/167.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2710396
URL: http://h170578.srv22.test-hf.su/167.exe
URL Status:Offline
Host: h170578.srv22.test-hf.su
Date added:2023-09-08 04:46:05 UTC
Last online:2023-09-14 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-09-08 04:47:05 UTC to admin{at}host-food[dot]ru)
Takedown time:5 days, 22 hours, 11 minutes Bad (down since 2023-09-14 02:58:37 UTC)
Tags:dropped-by-SmokeLoader Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-13n/aexe 9c3fea577cb0153c6ff64cd0ac690aabae967e45dd1f405504783fee674980e9Virustotal results 42.25% Stealc
2023-09-11n/aexe 27988ff034a475c472331c18c5ceb74623595f62d57c7702339cb4da5bbd6bc7Virustotal results 43.48% Stealc
2023-09-10n/aexe aef16c0c7295575a58ce7e963c271b5007589ac404af1ec5a186a34ff080fb7dVirustotal results 42.03%Stealc
2023-09-08n/aexe 9658ef9d99a1668dfac911a61fe9a1184257946a10bdffafaa5f27eb54a28467n/a Stealc
2023-09-08n/aexe e1ca58eccb42ff2a1afb121bed6b78949102aaf06dedcd10d36149f8e9a4b3b8Virustotal results 46.48%Stealc
2023-09-08n/aexe 97768c478c5e2eceaf19c74c3e75b871d8c7028f3a83f6ff5ce74fd1aa6860c5Virustotal results 74.29%Stealc