URLhaus Database

You are currently viewing the URLhaus database entry for https://arabianairlanes.lol/test.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3708495
URL: https://arabianairlanes.lol/test.exe
URL Status:Offline
Host: arabianairlanes.lol
Date added:2025-11-14 18:40:19 UTC
Last online:2025-11-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Botnet C&C domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-11-14 18:41:14 UTC to abuse{at}altawk[dot]com)
Takedown time:1 day, 15 hours, 2 minutes Poor (down since 2025-11-16 09:43:52 UTC)
Tags:c2-monitor-auto dropped-by-amadey WallStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-15test.exeexe ed84773d3e8211de7519330f416f85143da8f0f90410595e7ab72de9ac05d5b2n/aWallStealer
2025-11-14test.exeexe 19f6b92a842e6bf50f9b91c5028862259ed98aa7a09759711adbc58fd97d1e17Virustotal results 20.83%WallStealer
2025-11-14test.exeexe d485217891bdd5dde6ab8c256fd8618be941905fb4c89513e7c14b42c0ee9f06n/aWallStealer