URLhaus Database

You are currently viewing the URLhaus database entry for http://noahhausner.icu/timeSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2735111
URL: http://noahhausner.icu/timeSync.exe
URL Status:Offline
Host: noahhausner.icu
Date added:2023-11-24 20:11:07 UTC
Last online:2023-11-25 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-25 06:43:05 UTC to abuse{at}simplecloud[dot]ru)
Takedown time:1 day, 17 hours, 19 minutes Poor (down since 2023-11-26 13:31:39 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-26n/aexe 9d4b3b956471d7e851215b47b39e378f9ef22365de1ff9a12e4376994a4cbcc6Virustotal results 43.66%Stealc
2023-11-26n/aexe 39e0d9c8beb12b8fa99310db9c8474d7ebcfd75d9c592f7f6fb97cc469b5e5e0Virustotal results 40.28%Stealc
2023-11-26n/aexe 0aa234562ce0bf67d4e737f8624d36246595aaada2600636f95edece48fe141dVirustotal results 38.89%Stealc
2023-11-26n/aexe 9dafcb04e5b1bbbeb3a56ace34abd41892bf5e422f2b4bfe57800aa825967e7cn/a 
2023-11-25n/aexe abdff7348eeb504f388224f2d33849eb2b8e661176a3e7c83d00a7aefe8a4caeVirustotal results 41.67%Stealc
2023-11-25n/aexe 2d4d0d71a305d067656e93ab37ffb9793d025beebc1c8f21d37777e7b0471180Virustotal results 41.67%Stealc
2023-11-25n/aexe 07cfe98212136c2530608c2ef759f9a6ca5573027896f9a53c5b9c70c7d475a7n/aStealc
2023-11-25n/aexe dd447ea1ac60721efa84d80d3101e7f79eb2d86785df2358cddbe04809a283c7Virustotal results 40.28%MarsStealer
2023-11-25n/aexe dfd763607915c16c88b819170639b828a72f02196be6e123318cc70633ce17fbVirustotal results 51.39%Stealc
2023-11-25n/aexe 3b13f1afc77c4d537fb4b1488846b042cbdf604345954541af429fd21418e9b6n/aStealc
2023-11-25n/aexe 9498399e00f48252d440863a0192975037222a1e30cbcf24b49f16480aa1ece7Virustotal results 47.22%MarsStealer
2023-11-25n/aexe 509da045b3985f51bd0e3646d66f3d5a5efc2964d53afe1b737427a2aba6e914Virustotal results 43.06%Stealc
2023-11-25n/aexe 2bd90ebb9e56d79b4f68f92a47c8d78c97a0d4290966325c0c49744bc21b491fVirustotal results 45.83%Stealc
2023-11-25n/aexe 772ec57ae0bf39c7e670ffcd35667deebf39e5cad531bf6f114393ec92b901f6Virustotal results 35.82%Stealc
2023-11-24n/aexe d381efbc2ea684b34bd852804284d9a9a27ce458be61ee375268d76681bec748Virustotal results 37.50%Stealc
2023-11-24n/aexe 1ecf32c1650e2c9b0a47cdf39b0c22e8f92e95a115bdbc89988da52ab755139dn/aMarsStealer
2023-11-24n/aexe 5a08016b7110cf63c4e5fca8976b9afc9d6da94650ffb9e14129b30364e939a2Virustotal results 47.22%Stealc
2023-11-24n/aexe 3d664fa0cec81f33f5d79de5e3a3cb060f54c442a90ba84c712fea2d9861410aVirustotal results 50.00%MarsStealer
2023-11-24n/aexe ce8e42ad172f788ff8f4e9b434320fe9db4a5b549b56759e3d992f5e770d0d24Virustotal results 51.39%MarsStealer