URLhaus Database

You are currently viewing the URLhaus database entry for http://jask.powerforxes.shop/malesa/66ca202b71c36_HP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3212779
URL: http://jask.powerforxes.shop/malesa/66ca202b71c36_HP.exe
URL Status:Offline
Host: jask.powerforxes.shop
Date added:2024-10-04 19:16:33 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 19:17:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 21 hours, 27 minutes Bad (down since 2024-10-22 16:44:26 UTC)
Tags:exe Stealc Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-21n/aexe e13c19f505b875722ff6c62616ac5ca51b918c5af1f8e2f86855de49627ebc4an/a Stealc
2024-10-19n/aexe 5aa9fe71e8cc57cebbce2e2d6bec27ff76524077af138c402def45d6f990e261n/a Vidar
2024-10-17n/aexe 5408c3dd88422a812913f30b158905027fabf9518d07178f1a45fd1dcabae565n/a 
2024-10-16n/aexe ccc88f40b4e1e22d1ec97f3156a4541cc978d6915df597beea731a171e099befn/a Vidar
2024-10-14n/aexe cb5f893d9a7c0327e71ef57378fb497fa395d3c68185c167c830f5bd48e2d5c6n/a Vidar
2024-10-12n/aexe 76857e5d22b84d507656e221f5c0944435b93d5c069872a0fa3d92b8579e5820n/a Vidar
2024-10-04n/aexe dbbacaf728af45c13e7aa9538090d6795d4fa7ace887d6f0823007a55414a1a1Virustotal results 82.19%Vidar
2024-10-04n/aexe c2a20beea197fb6e70755b9778cae1f06786c62404cb5345ac36f253336d937an/a Vidar