URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.66.47/files/file300un.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2862267
URL: http://5.42.66.47/files/file300un.exe
URL Status:Offline
Host: 5.42.66.47
Date added:2024-05-24 09:27:10 UTC
Last online:2024-06-11 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-05-24 09:28:09 UTC to abuse{at}lethost[dot]co)
Takedown time:18 days, 10 hours, 32 minutes Bad (down since 2024-06-11 20:00:22 UTC)
Tags:64 AsyncRAT link exe PrivateLoader PureLogStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-06-06n/aexe 93fa3e478774a78c8aebf44604bb498254abe707b0bba06e5c43d40708888334Virustotal results 57.35% 
2024-06-05n/aexe 23fa195be652ef4af44a1f80ebfde631584e6ddd3b014f14af6fc4ac7605d584Virustotal results 28.38% Adware.Neoreklami
2024-06-03n/aexe 2b158df3b782217e02b5c436f0e00a2fc7561e95da7f2369f4fa2920cf1a20b0Virustotal results 40.54% AsyncRAT
2024-06-01n/aexe 30ffca4d25603e479223ababa825b47e2f65b37f24778ea07ce19a9c68494e3aVirustotal results 16.44% 
2024-05-25n/aexe b00ba7382dff5cb4acd3feb144edf4a172434c7e3f44971387596bf0dce60865Virustotal results 10.96% 
2024-05-24n/aexe bf361d860a7ae257d6d7694cea54a556b77b8185e8677bd9f1752415884ede81Virustotal results 13.51%PureLogStealer
2024-05-24n/aexe 803af90de603592cfdca6c9b6a8ffc39130a54dee552f0758f7ebf07ab327fc5Virustotal results 27.40%PrivateLoader