URLhaus Database

You are currently viewing the URLhaus database entry for http://193.233.132.234/files/Uni400uni.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2819427
URL: http://193.233.132.234/files/Uni400uni.exe
URL Status:Offline
Host: 193.233.132.234
Date added:2024-04-20 09:52:13 UTC
Last online:2024-05-05 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-04-20 09:53:07 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:14 days, 22 hours, 59 minutes Bad (down since 2024-05-05 08:52:50 UTC)
Tags:64 Arechclient2 exe gcleaner link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-28n/aexe 8408dcfb8751f971ab0f3f4ec16abc52586a90a507ac8e6be0b02219980758f3Virustotal results 9.72%Stealc
2024-04-26n/aexe 73e9463ce5ada7f99d693375e99bb7fa71624cd061c3cde643a2fd0083c5d1d7Virustotal results 7.14% GCleaner
2024-04-25n/aexe f6bfa172fb2a124980f8134f6b5c765e7af52133a0c828e87d05b40a1a3f5005Virustotal results 18.57% 
2024-04-24n/aexe 6a5ea5ad3f7047f3d6e40bb3de551ec20db45a01536b96a44f557a4ae3729352Virustotal results 4.29% Stealc
2024-04-23n/aexe 97655f76dbd6e322aea5ecf9dcc82420ec25fb67c6fec0a6febbcd7e8b632e53Virustotal results 7.04% 
2024-04-22n/aexe d393c369fcce5b961018081cd6b15105eed1cc2a74ff235beb5439be050393dcVirustotal results 10.14%Arechclient2
2024-04-21n/aexe b79b3ab665881eadd15b67b9b105db7d99eb091905350a53c6bbc7b91a42cd48Virustotal results 25.35% Stealc
2024-04-20n/aexe 6b7baa1db0d2ed5c12dfb8f289449384ff821110f9b490379c5fcd9190090f4eVirustotal results 28.57%Stealc