URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.64.2/api/files/software/s1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711745
URL: http://5.42.64.2/api/files/software/s1.exe
URL Status:Offline
Host: 5.42.64.2
Date added:2023-09-14 21:26:05 UTC
Last online:2023-09-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-14 21:27:05 UTC to abuse{at}lethost[dot]co)
Takedown time:1 day, 19 hours, 48 minutes Poor (down since 2023-09-16 17:15:34 UTC)
Tags:32 exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-16n/aexe a93d245e23348d656399808c1f2fc38314163d710ed7d496af24528ac1b9e9ccn/a OnlyLogger
2023-09-16n/aexe 9575b55ebf6004f3f86ecd981b47092ea58feb022e6138b8a1c1b62e34687fb2n/a Stealc
2023-09-16n/aexe 898e5a654f6e38267a8718a818d2c61a80ba8c2be631d7caf73cd900c5fb996cn/a Stealc
2023-09-16n/aexe cb760f7c71af8c1c5fc901cd0a6e8e23f7bfcab641c0ad95462450e94cadc1d1n/a OnlyLogger
2023-09-16n/aexe 1c5726254e6159c045bcf692be0654dd8e2154ca0f6e89b734334944d5b7eb26n/a Stealc
2023-09-16n/aexe 192fc1fd53212188b7eb6d9a993d7a1fba63809d3e170b6c817900b778446775n/a Stealc
2023-09-16n/aexe 96aee723f4e99b71d216411e44fa8f10a9ce7a01df947cc0c41aa8856076fa1en/aStealc
2023-09-15n/aexe deaba172b40976a5047522f4cf3b8502d989de94fb875ce3ae4037a1b8382a0fn/a Stealc
2023-09-15n/aexe 54c45269002b84d18f7c86809a608d13fe641a2a6c0e25a31b2e9fd49eac390cVirustotal results 45.07%Stealc
2023-09-15n/aexe dc7462bfef0b3d00d800f683b842eecc96c1839a12342f4decb0b88344297925n/aStealc
2023-09-15n/aexe 561d0712bfdce76c6309a6d0cf1d53686077e01980952856299ceee81f880d02Virustotal results 42.86%Stealc
2023-09-15n/aexe bb0f86837a1d287e012a271347d5326d578719624dfadf031a006e21f6f8f611Virustotal results 44.29% OnlyLogger
2023-09-15n/aexe 97362d92be5f792fe05c5d4a4ee7e702528b5591c5152a2c5b0f59da9b5dd0fbVirustotal results 45.07%Stealc
2023-09-15n/aexe 719fb7835d487d0614236063c966637e44681f6c1924ba4706c6d01a76fac8feVirustotal results 45.07%Stealc
2023-09-15n/aexe 9b2cd6f9d153ff961cfefc5a5fb538e9470fefb2ad19f516f64dc6bcea8245a8Virustotal results 44.29%Stealc
2023-09-15n/aexe af6e8f425fcb23cf384ca01f55ed5d1eb561b7ecbfa48264ecd8b51e460953f3Virustotal results 40.85%Stealc
2023-09-15n/aexe 1f6e1c0b0d5aa36e3eb96ec825979dd28708170c2fe1e726169361480b6d3693Virustotal results 39.44%Stealc
2023-09-15n/aexe 652ed9fea38372018ce53bcd4e7bcf562fa3446714fd894ab77ecbea7fe50b34Virustotal results 38.03%Stealc
2023-09-15n/aexe 98ec96ba074e1edbb26f8466ba001fb0a495f932878a2bf201da5f17424fe59fn/aStealc
2023-09-15n/aexe 5f3892f2aeaa6ac6f1c6b26d85cb50957381585376f4a23209c5d6c6219fc1bdVirustotal results 36.62%Stealc
2023-09-14n/aexe 9e89c31df9863bff75a294fdf1700a0a18607a0ddbf1bab54426a834c758e592Virustotal results 40.85%Stealc