URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.67.23/oorigg/univ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2850339
URL: http://5.42.67.23/oorigg/univ.exe
URL Status:Offline
Host: 5.42.67.23
Date added:2024-05-14 23:49:05 UTC
Last online:2024-06-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-05-14 23:50:12 UTC to abuse{at}lethost[dot]co)
Takedown time:1 month, 13 days, 16 hours, 50 minutes Bad (down since 2024-06-27 16:40:58 UTC)
Tags:32 exe gcleaner link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-26n/aexe ccd0c8b308f9160431acaba610ac55f83e5ae230fb8c5864718fd902fad6c11cVirustotal results 59.46% GCleaner
2024-05-24n/aexe 3ad9c662c1b0a6e0bc238ecbad6a42334fa579ad9d0590c75fd5afb266795002Virustotal results 60.27% GCleaner
2024-05-24n/aexe 04879f466ebd32e95d463be48da17fe4d3e473eeb554c0820efff79dce5241c9Virustotal results 59.46% GCleaner
2024-05-24n/aexe dc0dd5fb80fd24bd185f3990eb25421fae984497c0eb791b7bca26444cb5261eVirustotal results 59.46% GCleaner
2024-05-18n/aexe 83eb35b8ea555b380c63d4adfcb4d8435819888e7566b4249dbe8fd08a58208eVirustotal results 56.94% GCleaner
2024-05-15n/aexe d30014c5b8ee418b092523a38e1fa8def881cb489522758d407cec4a4c28b129Virustotal results 53.52% GCleaner
2024-05-15n/aexe b1797826fee88484e2ce6b3587c99602c8f37709bc732fc9524cc299828b553eVirustotal results 54.79% GCleaner
2024-05-15n/aexe ee14c781b069355ef95988e86b59a4a388373178b7e047c88d28fc3ac8e4a93fVirustotal results 54.17% GCleaner
2024-05-15n/aexe cf1bd970f67135d6947f03a80f4a6b5d5cf7cdd3d135c36378841c52269067ddVirustotal results 54.79% GCleaner
2024-05-14n/aexe 87137f8ac515457f952efd992e0efcb3373337f7a311e27ba61b36e7f31033f3Virustotal results 54.79%GCleaner