URLhaus Database

You are currently viewing the URLhaus database entry for http://h171145.srv22.test-hf.su/timeSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2721633
URL: http://h171145.srv22.test-hf.su/timeSync.exe
URL Status:Offline
Host: h171145.srv22.test-hf.su
Date added:2023-10-17 15:03:06 UTC
Last online:2023-10-28 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-10-17 15:04:05 UTC to admin{at}host-food[dot]ru)
Takedown time:10 days, 10 hours, 8 minutes Bad (down since 2023-10-28 01:12:13 UTC)
Tags:dropped-by-SmokeLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-26n/aexe 53dc29187191f04860a12fcec1d810f8c2e6b827dfc1d3c06471c6b865b96897Virustotal results 43.06%Stealc
2023-10-25n/aexe 983f2e6c6459bc7ff4090afd1ccdb88b1784ba22dbe54e22b6f648945bfd23caVirustotal results 45.71%Stealc
2023-10-23n/aexe 3a72dc7c3caeca146124318f5e57d918cd662c8bdb357852ee3a52e02cf73523n/a Stealc
2023-10-23n/aexe 6a37fb22ba4cf331c954a84f31a730bce22d16a8b86833488c0724f50a338fe7Virustotal results 48.61%MarsStealer
2023-10-19n/aexe 316d90bb02fe3411fbe36c0ed10b9f9d00d6a4bcb121f872a57b11180eace5e1Virustotal results 47.89%MarsStealer
2023-10-19n/aexe 8f1b134304061a1b6837f7f9dec2c73a6af00b285d1e60bba2bd1aa89d79ea5bVirustotal results 42.86%MarsStealer
2023-10-17n/aexe 64774aae4c0db099f244f96e6748ae04765b12472197d1dcd537e6a1595339dbVirustotal results 47.22%Stealc