URLhaus Database

You are currently viewing the URLhaus database entry for http://171.22.28.226/download/rise/StealerClient_Sharp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715055
URL: http://171.22.28.226/download/rise/StealerClient_Sharp.exe
URL Status:Offline
Host: 171.22.28.226
Date added:2023-09-29 12:38:05 UTC
Last online:2023-11-06 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-29 12:39:08 UTC to matrixllp{at}skiff[dot]com)
Takedown time:1 month, 7 days, 23 hours, 34 minutes Bad (down since 2023-11-06 12:13:54 UTC)
Tags:32 AgentTesla link exe risepro

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-19n/aexe a831bdc4cc298ed6563d6b3c1b0124dd4efdb71fc00af3f0a4894c1dd334350fVirustotal results 37.50%RisePro
2023-10-13n/aexe 73b0e109f9585e58b6ca1e2b2a1cf11ec951eeb17d654a6ec12c5c06c9251bb2n/a RisePro
2023-10-11n/aexe ffabc05820d6d2218df2f828aa2762d8b17dfa99eb52d3df7135e9e9420d33d9n/a 
2023-09-29n/aexe 92462821c6baea822ee3335568750b1707eab65245b55e19f4b2456d9f3dc0d2Virustotal results 77.78% AgentTesla