URLhaus Database

You are currently viewing the URLhaus database entry for http://h171326.srv22.test-hf.su/timeSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2726604
URL: http://h171326.srv22.test-hf.su/timeSync.exe
URL Status:Offline
Host: h171326.srv22.test-hf.su
Date added:2023-10-30 07:06:05 UTC
Last online:2023-11-06 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-10-30 07:07:05 UTC to admin{at}host-food[dot]ru)
Takedown time:7 days, 2 hours, 34 minutes Bad (down since 2023-11-06 09:42:02 UTC)
Tags:dropped-by-SmokeLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-06n/aexe 60e849b6b7e737311a2e0e5bd6a76954455420003063da07f1ca1b5d00fa7f9dVirustotal results 38.89%MarsStealer
2023-11-05n/aexe e21e02d5e76167ff0fb6b1a534f48249558aab9e9950845ce4b0c77e79864f25Virustotal results 43.06%Stealc
2023-11-05n/aexe b2880d24019913e08f0abb9b7f6595faef75de3199269f092e315e13bea5e099n/aStealc
2023-11-05n/aexe 2bee29bac294615a9d1b613ba775972cda26781938e3ae3aa60ad9737f1fbde8Virustotal results 48.61%Stealc
2023-11-04n/aexe 56a6193fa150519df0ef9043094a2235855d6cb3fca36a4bfcb73cc57e800831Virustotal results 40.28%MarsStealer
2023-11-03n/aexe f7ba95f0e91ac4ca37c1615a5e09c3da8b9e2a495e52a5e1db142fc85f8b9a8eVirustotal results 40.28%Stealc
2023-11-03n/aexe 5166d61c8b8b42bb7fc4c61847cac83c284031d523e8998633b01e0af6e02e8dVirustotal results 40.28%Stealc
2023-11-01n/aexe f84d3179e6b58dec9a4e2e862ef03a531330540e80e099f5c0d9ae54492f5e2fVirustotal results 38.89%MarsStealer
2023-10-31n/aexe e4afe296a82993d386d4619f8a91152ac7da03a2dcf52c7eaee4397796d0f32dVirustotal results 40.28%MarsStealer
2023-10-30n/aexe 63a2fa37393b054082a377b69657728756be5dbcca6c271eb80779a2bea1fb44Virustotal results 40.28%Stealc
2023-10-30n/aexe a26dc029cbda5105a0cb0a4a21b0f0001e6b1d957c5b5f8196cf01ea7b039d15Virustotal results 40.28%Stealc
2023-10-30n/aexe fafe7d66e5bd7b863c859d329c390978d7e2db8627664e1427f7f184ba7dc24eVirustotal results 44.44%MarsStealer
2023-10-30n/aexe 546a88deccac12d32cb3a91f1216e63753d3b221d8f20b63b455bc76f3601becVirustotal results 62.50%Stealc