URLhaus Database

You are currently viewing the URLhaus database entry for http://193.56.146.210/mel/starka.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2560109
URL: http://193.56.146.210/mel/starka.exe
URL Status:Offline
Host: 193.56.146.210
Date added:2023-03-06 10:03:12 UTC
Last online:2023-03-06 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-06 10:04:09 UTC to info{at}janeirollc[dot]ru)
Takedown time:9 hours, 30 minutes Good (down since 2023-03-06 19:35:03 UTC)
Tags:Amadey exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-06n/aexe 58c0a5ca9f67dc4e326aec563394a9ac10a7d04fb9abe32dae0494233f009486n/a Amadey
2023-03-06n/aexe 60ef37755c5fc2cef0066ffca957752e75ae2e9f9f411d28328df3502f2e5337n/a RedLineStealer
2023-03-06n/aexe a25a1b89b62ab00e9fa5e08b111e584a84fd36649eca67ec56c4173d37c969aan/a Amadey
2023-03-06n/aexe d83c02d4a9a9a453eef0246954fb2d0c119ecc24b3a42e0fb8ad7bd18bdf43aan/a Amadey
2023-03-06n/aexe 6e537f8a75fdbb9f6a3cceab6bdfd31e54e1ddeb8f013fbbe7c6d6a5f1d2bf64n/a Amadey
2023-03-06n/aexe 820fe3ac6c45fc1ed547de500f949780b4e1535e5429441ba50ff42adbc8b419n/aAmadey
2023-03-06n/aexe c6a2d88ca5315aa555335addc8e834dcb1da654fa467e7d17decfa97df9594aan/aRedLineStealer