URLhaus Database

You are currently viewing the URLhaus database entry for https://defender-temeerty.sbs/test.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3709865
URL: https://defender-temeerty.sbs/test.exe
URL Status:Offline
Host: defender-temeerty.sbs
Date added:2025-11-16 10:32:08 UTC
Last online:2025-11-18 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Botnet C&C domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-11-16 10:33:16 UTC to abuse{at}altawk[dot]com)
Takedown time:2 days, 1 hours, 22 minutes Poor (down since 2025-11-18 11:55:33 UTC)
Tags:9a8fe7 dropped-by-amadey WallStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-17test.exeexe 9bbb8a3ef2b3d714bfb5ec3ad3cf97ac4adabe1e7713a039beea0c16d96919b7n/aWallStealer
2025-11-16test.exeexe d3b185b55f842d5d6ba61dfaf312bd74017f65a509df0376d7179ef7e19f9d93Virustotal results 13.89%WallStealer
2025-11-16test.exeexe 2fd8f169da9bf8ddd00d65c1164f285a20060fcd9622e64f1776a0cbec52b347n/aWallStealer