URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.67.7/oorigg/univ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2755635
URL: http://5.42.67.7/oorigg/univ.exe
URL Status:Offline
Host: 5.42.67.7
Date added:2024-02-02 20:33:05 UTC
Last online:2024-03-30 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-02-02 20:34:05 UTC to abuse{at}lethost[dot]co)
Takedown time:1 month, 26 days, 14 hours, 11 minutes Bad (down since 2024-03-30 10:45:08 UTC)
Tags:32 exe gcleaner link Nymaim link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-28n/aexe ac9ebbadbf39ef79f2ed85ab64dd75bc2fcc0d39e2cff6316e777941b3ff622aVirustotal results 58.33% GCleaner
2024-03-04n/aexe 07d8bd00c483ea18b026a42346905d245b84dcfbfe6290b215222f3979a8886an/a GCleaner
2024-03-03n/aexe 58df6a2e1a397e353fdef4f64f43a60173507d21c69946ac70e7ed8968f27db0n/a GCleaner
2024-02-27n/aexe ca50ae7788dcdf9e9106343678e91a84a5cbeb1e7d97316ced14476365384aean/a GCleaner
2024-02-20n/aexe c37679e78f6af5ba63dedfdfa3c66327626f6a4afa19359ca80d02ae5e1f827an/a GCleaner
2024-02-08n/aexe 3d7acc666b99eff985507c8504a8b71d9c7ba1f10897e17fce86f87c87205745n/a Nymaim
2024-02-02n/aexe 8d2a28f4d0d93aaf2e4dedf67b40ba16a68026a27e8b70ab1e82bf244d533682Virustotal results 57.75%GCleaner