URLhaus Database

You are currently viewing the URLhaus database entry for http://playd.healthnlife.pk/ldms/956d73b7f041.exe#default15st which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3206696
URL: http://playd.healthnlife.pk/ldms/956d73b7f041.exe#default15st
URL Status:Offline
Host: playd.healthnlife.pk
Date added:2024-10-03 09:51:06 UTC
Last online:2024-10-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-03 09:52:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:22 hours, 52 minutes Good (down since 2024-10-04 08:44:24 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe 6749b860c117f01f685ac5a600974d8fdd2a86fb6e284a735dfff45a15a5d863n/a 
2024-10-04n/aexe b79da056da8964c906f095ad3d2a07a5f58eaa38aefa7bdd9645aa3c17fc6a42n/a 
2024-10-04n/aexe 2afec46beb829a4fcc2ff06b2e6f3c6634626dcb384a8ceb57eb0a23af0a8c3bn/a 
2024-10-04n/aexe d7c3b43c4f17103c684ca2d191495a216030d927d7ef34c67384833c19e99321n/a 
2024-10-03n/aexe d498d07e1ddb734daef7968a218620d9251d480b0f10f1838365bfbd3387aba6n/aStealc
2024-10-03n/aexe efe244435543988eec7afe37d51601aa1c44760b35b75926e3ed11325120271fn/a 
2024-10-03n/aexe 4e68e5d5a6e5124a85673f7b5bff1d0915a86f9e38520ff869353f834187b807n/a MarsStealer
2024-10-03n/aexe 9a9a00de899875e4cc8ea6bac86f8950ff701c07349baef3d9a1fdf158dc6386n/aMarsStealer