URLhaus Database

You are currently viewing the URLhaus database entry for http://62.204.41.150/ScreenUpdateSync.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3224144
URL: http://62.204.41.150/ScreenUpdateSync.exe
URL Status:Offline
Host: 62.204.41.150
Date added:2024-10-07 23:11:06 UTC
Last online:2024-10-08 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-10-07 23:12:10 UTC to abuse{at}changway[dot]hk)
Takedown time:9 hours, 10 minutes Good (down since 2024-10-08 08:22:11 UTC)
Tags:exe Stealc ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-08n/aexe 100f1c346cbcff15f4d9d75c791000625850e1c82b44ce9427ccf441f5c3cb79Virustotal results 37.50%Stealc
2024-10-07n/aexe 55499b49482b8743ff2545f0bad3bf1197a33ef0d5d5bf421383e22521fed0e9Virustotal results 37.50%Stealc