URLhaus Database

You are currently viewing the URLhaus database entry for http://tamk2op.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712303
URL: http://tamk2op.top/build.exe
URL Status:Offline
Host: tamk2op.top
Date added:2023-09-18 10:21:09 UTC
Last online:2023-09-19 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Gi7w0rm
Abuse complaint sent (?): Yes (2023-09-18 23:14:04 UTC to support{at}ruvds[dot]com)
Takedown time:1 day, 0 hours, 13 minutes Poor (down since 2023-09-19 10:35:58 UTC)
Tags:ArkeiStealer link stealer viaSmokeLoader Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-19n/aexe 642e2d20693570de6da886a066d485fcab2afc9bf0970c3c0b923bd88f11e25bn/a ArkeiStealer
2023-09-18n/aexe 35914b401b7417ee4ff4993d61497bcd8b046b9c68798fc66c545a721bcf7368n/a ArkeiStealer
2023-09-18n/aexe 22151a4ebc1dacb53aa0718c44a135b5fbe5300af6c40261b362a5adcf0f5a41Virustotal results 39.44% 
2023-09-18n/aexe 5b4bced547eb17aa796a64c58e89f9d96e56edab6596e02ec13801bf5d452b97n/aVidar