URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.64.17/files/Uni400uni.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2812590
URL: http://5.42.64.17/files/Uni400uni.exe
URL Status:Offline
Host: 5.42.64.17
Date added:2024-04-15 05:51:05 UTC
Last online:2024-04-26 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-04-15 05:52:05 UTC to abuse{at}lethost[dot]co)
Takedown time:11 days, 0 hours, 50 minutes Bad (down since 2024-04-26 06:42:41 UTC)
Tags:exe glupteba link opendir Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-21n/aexe b79b3ab665881eadd15b67b9b105db7d99eb091905350a53c6bbc7b91a42cd48Virustotal results 25.35% Stealc
2024-04-20n/aexe 6b7baa1db0d2ed5c12dfb8f289449384ff821110f9b490379c5fcd9190090f4eVirustotal results 28.57%Stealc
2024-04-17n/aexe b925abb193e7003f4a692064148ffe7840096022a44f4d5ae4c0abb59a287934Virustotal results 11.27%Glupteba
2024-04-16n/aexe 09d272c4183194a8fe293f975affd4033d2a7319c4efae07403170edc16ff50fVirustotal results 12.86% 
2024-04-15n/aexe b1bf0f6717341cb605ebf48e85805282b77e5a3d610f211b90e4ec726b448331Virustotal results 34.29%Glupteba