URLhaus Database

You are currently viewing the URLhaus database entry for https://dewatabalirental.com/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3259725
URL: https://dewatabalirental.com/2.exe
URL Status:Offline
Host: dewatabalirental.com
Date added:2024-10-28 14:03:22 UTC
Last online:2024-10-30 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2024-10-28 14:04:09 UTC to abuse{at}egihosting[dot]com)
Takedown time:2 days, 8 hours, 14 minutes Poor (down since 2024-10-30 22:18:49 UTC)
Tags:exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-30n/aexe 55ce981c82c47282ff938ef1d0b81ba7f644f37dd6c88132d36e9df7e70dc886n/aStealc
2024-10-29n/aexe 9001d11fb0f26a947bac4426a9ae47d56d296056ae2f91c4d864f6ceeb95a951n/aStealc
2024-10-28n/aexe a8bfb588ac2006a3634cf50fcf144459cb4a748ef4b69c3c8170efcf4666438dn/a Stealc
2024-10-28n/aexe b32b753d94dc0a02f097626fa793432be53d5927d30abc5490a2d44a055670e5Virustotal results 12.50%Stealc