URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.64.35/InstallSetup9.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2739055
URL: http://5.42.64.35/InstallSetup9.exe
URL Status:Offline
Host: 5.42.64.35
Date added:2023-12-09 07:20:37 UTC
Last online:2024-01-14 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-12-09 07:35:07 UTC to abuse{at}lethost[dot]co)
Takedown time:1 month, 6 days, 11 hours, 34 minutes Bad (down since 2024-01-14 19:09:43 UTC)
Tags:exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-01-08n/aexe eb8daa3bbd914c5356559929d7fd7e1132c9b0f7196fc12c779256bd4412c71dn/a Stealc
2023-12-26n/aexe 69a94b658bce41d361945a1594fdc801209d8719ae67df8d2d3df5056e9b0537n/aStealc
2023-12-21n/aexe ee2f89ac8b23d35330a44b6b53b0afed4b4a908ee16b844e4edb0faadf494a3an/a Stealc
2023-12-21n/aexe 75da34a9df70ab3f2ad0d14e314813d3ed15677a4b3520c0d2a62baddf7eff69n/a 
2023-12-20n/aexe ea86e8c7ba29632068d5e69f07325c733ee3299ace4aab4521f137dde210a8cbn/a 
2023-12-11n/aexe 900c0640ba1e682128403dd48d4865aa07f3a63086c7e19bc8baa0ca79bd6cdfn/a Stealc
2023-12-09n/aexe 920518d1d39ab709e1cd880b133377840aaceb7e25540a548b8134cf4182a791Virustotal results 55.56% Stealc