URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as Ligolo.

Database Entry


Signature:Ligolo
Firstseen:2024-09-28 07:38:08 UTC
Lastseen:2026-04-12 09:35:12 UTC
Unique Payloads:17
URLs:15

Payload


The table below shows all payloads that have been identified as Ligolo.

Firstseen (UTC)SHA256File TypeFile sizeVT
2026-04-12 09:35:12b601d17b3a0f8d870965dd825145a2c90d85b8f4ff6a713f2fc0ea28d093660aExecutable exe10'944'000n/a
2026-03-20 10:44:074b41f36f82db6da8767a0a1c2997c8242d80b2d10a8f1d28c252a9306ec152b5Executable exe7'302'656n/a
2026-03-03 09:41:104b41f36f82db6da8767a0a1c2997c8242d80b2d10a8f1d28c252a9306ec152b5Executable exe7'302'656n/a
2026-01-01 00:46:150b74e5aa8e84ddefd60a6663e6305b3615eb743db543323f8a0068b58d56503fExecutable exe7'192'576n/a
2026-01-01 00:46:12f6fdfedea8efb0eb9b409267ea545ff09272c9a6ba59d9ffc9454c85c70deb18Executable exe7'192'576n/a
2025-11-29 10:30:1248868c98dfabd703031587cffdbe5ca26ac180a15e89a52e59915710f1836f28Executable exe6'694'400Virustotal results 45 / 72 (62.50)
2025-11-04 17:07:24bb8d408a966628daa0d1842e3f70a3a534de7600c2b6484722d0b82956160f9eExecutable exe5'545'984Virustotal results 48 / 72 (66.67)
2025-08-18 14:31:25561b9635f3dc9faccf203e4bae11aca8a1e1e4caacbfd7ab7e75f4cfbaabfb50489n/a
2025-08-18 14:21:099de8bbc961ff450332f40935b739d6d546f4b2abf45aec713e86b37b0799526dExecutable exe10'684'928n/a
2025-08-04 11:42:25123901fa1f91f68dacd9ec972e2137be7e1586f69e419fc12d82ab362ace0ba9Executable exe10'683'392Virustotal results 42 / 71 (59.15)
2025-08-01 10:56:1540d4d7b0bc47b1d30167dd7fc9bd6bd34d99b8e0ae2c4537f94716e58e7a5aeb770Virustotal results 3 / 62 (4.84)
2024-12-02 20:43:474b46df0230d98147d6955c78e5d56143bb394040de319cf980611f8359f18a2fExecutable exe6'236'160Virustotal results 48 / 71 (67.61)
2024-12-02 20:43:18083dbfe9fbd1a94c640aa2e80c0304ac49d337b15f6f148c2f91d2c21a23cbb62'654'047Virustotal results 43 / 69 (62.32)
2024-12-02 20:30:1507578b1cafbcd0b82948604de2e952fc682589128a176dc91a7466f2169803756'029'312Virustotal results 30 / 65 (46.15)
2024-09-28 08:58:104b46df0230d98147d6955c78e5d56143bb394040de319cf980611f8359f18a2fExecutable exe6'236'160Virustotal results 40 / 73 (54.79)
2024-09-28 08:32:11083dbfe9fbd1a94c640aa2e80c0304ac49d337b15f6f148c2f91d2c21a23cbb62'654'047Virustotal results 30 / 68 (44.12)
2024-09-28 07:38:084b46df0230d98147d6955c78e5d56143bb394040de319cf980611f8359f18a2fExecutable exe6'236'160Virustotal results 40 / 73 (54.79)

Number of entries displayed: 17 (max: 1'000)