URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.151/ScreenDataSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3164578
URL: http://62.204.41.151/ScreenDataSync.exe
URL Status:Offline
Host: 62.204.41.151
Date added:2024-09-09 19:54:05 UTC
Last online:2024-09-14 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-09 19:55:11 UTC to abuse{at}gorizontllc[dot]ru)
Takedown time:4 days, 13 hours, 47 minutes Bad (down since 2024-09-14 09:42:44 UTC)
Tags:dropped-by-PrivateLoader exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-10n/aexe 4c05c9ade0f5fa4dda9a53c74f8bc41c3ab59d29203dc11c2f5cc99a5dbf7df1Virustotal results 19.18%Stealc
2024-09-09n/aexe d3b79435a3f7f45d17f4e21bffeacea894eb97bf3cda0e362d3a5ae11c736de1Virustotal results 15.07% Stealc
2024-09-09n/aexe 7886891d37ce47fee81d35a43449a95f993506c28a4a62eed0f53bc34ccdafa7Virustotal results 40.54% Stealc
2024-09-09n/aexe a5984de1d09d8df2b72ece2ebd866940524c67720ae2a91725745a34b9e3ceb0n/aStealc