URLhaus Database

You are currently viewing the URLhaus database entry for http://richardwalker.icu/timeSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2727390
URL: http://richardwalker.icu/timeSync.exe
URL Status:Offline
Host: richardwalker.icu
Date added:2023-11-03 07:02:18 UTC
Last online:2023-11-03 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-03 07:03:06 UTC to info{at}iqhost[dot]ru)
Takedown time:13 hours, 6 minutes Good (down since 2023-11-03 20:09:32 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-03n/aexe f7ba95f0e91ac4ca37c1615a5e09c3da8b9e2a495e52a5e1db142fc85f8b9a8en/aStealc
2023-11-03n/aexe d041a74ca833f465c230f7dda0a23a95581442277f8025e62ca79adebb5933b5n/a MarsStealer
2023-11-03n/aexe dc84380a46e1c26626db797d8e2f9e5e64096c5a79539e048e3ffb395b406e3an/aStealc
2023-11-03n/aexe 1671e83e843e98dadcebe0e45749120ca568409c3f8fbd60f5273aa6f8b7f589Virustotal results 36.11%MarsStealer
2023-11-03n/aexe 11600a65e9843dd9405b14825e0f8972e6843d18d56c919dde88e493d2a563abVirustotal results 34.72%Stealc
2023-11-03n/aexe 5aeaa349b8e610123b2093436bbce6b76f4a6cef193c266dbbc6888fdcac5b5bVirustotal results 34.72%Stealc
2023-11-03n/aexe 6a8d89dce793fe2b3dece3e933914a579153c8b26761c128d3b550d6a5e48995Virustotal results 37.50%MarsStealer
2023-11-03n/aexe 5166d61c8b8b42bb7fc4c61847cac83c284031d523e8998633b01e0af6e02e8dVirustotal results 40.28%Stealc