URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.64.17/files/file300un.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2812589
URL: http://5.42.64.17/files/file300un.exe
URL Status:Offline
Host: 5.42.64.17
Date added:2024-04-15 05:51:05 UTC
Last online:2024-04-26 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-04-15 05:52:05 UTC to abuse{at}lethost[dot]co)
Takedown time:11 days, 0 hours, 48 minutes Bad (down since 2024-04-26 06:40:43 UTC)
Tags:exe opendir Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-21n/aexe 4f47d84b03f5cfa3845d1b36df5e40df984756fc6ba2d98586eb39dced212628Virustotal results 25.35% Stealc
2024-04-20n/aexe 95442c887f47bbb4b350fca87c45dc6ef95355ce86a63d7c2f50db2d92ae512eVirustotal results 23.94%Stealc
2024-04-17n/aexe 2aca1abc45a264170f1e9dad15de072ed216b3f56e79f2a721da170c37f1d53dVirustotal results 10.53% 
2024-04-16n/aexe ec8acc6613d7b77e44d86d5ebc375b51a8fbcba8d35b8e74d84c8b766eefe506Virustotal results 17.14% 
2024-04-15n/aexe d562b3b44859f761645676e0c0e7daad1226c5b90f53b4fe5e5395bf77454ec7Virustotal results 28.57%Stealc