URLhaus Database

You are currently viewing the URLhaus database entry for https://pub-c7b31ab9decd4a2684fcd9fc90862261.r2.dev/setup.msi which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3486178
URL: https://pub-c7b31ab9decd4a2684fcd9fc90862261.r2.dev/setup.msi
URL Status:Offline
Host: pub-c7b31ab9decd4a2684fcd9fc90862261.r2.dev
Date added:2025-03-22 06:58:09 UTC
Last online:2025-04-14 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: aachum
Abuse complaint sent (?): Yes (2025-04-08 23:07:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 18 days, 13 hours, 27 minutes Bad (down since 2025-05-09 20:26:17 UTC)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-17setup.msimsi 7dc49d0117f63d5e81098cf9fda0eb68b0fb4ec3140a95c9827f61c047308ce9n/a
2025-04-16setup.msimsi 4dae70e47c6507ca31f82be1e1b8a3b9fb8d46ff10e112de50d3eae419546724n/a
2025-04-07setup.msimsi 8bf039b689e595a68b689e5863a08b6af89c194fe6937dc91b210f9c256298fcn/a 
2025-04-04setup.msimsi 576ff94bf1d82d99831613e0aec329181e94d72fc4141ea3ad79b26935a31dd6n/a 
2025-04-01n/amsi c82c1bbdd8cd271fa481780fd2960209690716e26dcb5028a1105e59db123988n/a 
2025-03-22n/amsi bf68660833d7514dd4d63ea43317a72511974985054e4d2f5838fd798cd9cf08Virustotal results 10.17%