URLhaus Database

You are currently viewing the URLhaus database entry for http://sdfjhuz.com/dl/build2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2791468
URL: http://sdfjhuz.com/dl/build2.exe
URL Status:Offline
Host: sdfjhuz.com
Date added:2024-03-24 18:08:05 UTC
Last online:2024-05-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: dms1899
Abuse complaint sent (?): Yes (2024-05-30 11:31:15 UTC to abuse[dot]tgsolutions{at}telefonica[dot]com)
Takedown time:2 months, 6 days, 18 hours, 3 minutes Bad (down since 2024-05-30 12:22:28 UTC)
Tags:exe MarsStealer Stealc Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-29n/aexe 8286d000d4045fe41788db22d353553ced31258eeaa0d52825e317f94d23dd9aVirustotal results 43.24% Stealc
2024-05-22n/aexe 1932c3563ac01b8278f40493ef7d3f78413f4d5e86b9d1e0483001bb07654bc2Virustotal results 43.24% Stealc
2024-05-14n/aexe 702189dc83cab221f127748e9c8edbed4799f8e29704e6c5800cb126192d754cVirustotal results 38.36% Stealc
2024-05-08n/aexe 6911aa07576ec3312eb53f6cd392db08b77db2aa7a2fc24d7abb94679b0c21d8Virustotal results 45.21% Stealc
2024-05-02n/aexe 27536978f40fa8420cede739bb96284e6538df0b57197fa4c2cea0202e2fb4fcVirustotal results 43.06% Stealc
2024-04-30n/aexe e95217e0e62d82df096a4fb8ac08b6d4d9643fe85b740b468435531d8b18d6c2Virustotal results 43.66% Stealc
2024-04-29n/aexe 4bc42f0c5e89980d4a5b007ba0dea54ec027ded485d4deaabacf5fa785bfbb22Virustotal results 43.06% 
2024-04-23n/aexe 998c38a88197ab545ed66959130ba09db2359000da1fe5b6af913a33d5902cacVirustotal results 41.54%Vidar
2024-04-21n/aexe 9b0da8ab12d9ca7cc05b9553ba3d3407e4ee38cb9a74298096022b2b46563fb2Virustotal results 39.44% 
2024-04-11n/aexe 3867daccc1b24b18c85e32326062ab84b53f3ef78a000966a0e0e95c40a20953Virustotal results 42.03% Vidar
2024-04-10n/aexe 4331e2d76abcc10cb5c933bcf01a180da40e0ec819e990762ed4b1b08fe70b1aVirustotal results 36.23% MarsStealer
2024-04-08n/aexe bb4a9f6071b8d7bf2a93f7a88accd28d2f5b9186f4d2b6f0d462c3dd4bc79739Virustotal results 45.71% MarsStealer
2024-04-08n/aexe 47dbbde31af72a2c7807f2d607ed16d665980e43f4437c147f2981efa33e548dn/a MarsStealer
2024-04-03n/aexe 31084adb877ef9bcf2143fa2d60ce8860d15af325424b709ad115febe8b96e81Virustotal results 41.43% 
2024-03-29n/aexe 2389dff2f3f5459ebb8110c01eeedee11ce0c75c3bb735f6f5f76f8a7bb6e9f6Virustotal results 37.50% 
2024-03-27n/aexe afce72cd3bc717c784962083066e3ede2b0aaadbe0908ec7360096c923774fa5Virustotal results 36.11%Vidar
2024-03-24n/aexe 03b38ccf2c3145839d5ea7c5ccec609de3a67a7e435e94ca05c8c080d9df4411Virustotal results 79.17%