URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.97/download/rise/StealerClient_Sharp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728745
URL: http://194.49.94.97/download/rise/StealerClient_Sharp.exe
URL Status:Offline
Host: 194.49.94.97
Date added:2023-11-07 08:11:07 UTC
Last online:2023-11-24 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-11-07 08:12:06 UTC to madhost{at}tutanota[dot]com)
Takedown time:17 days, 7 hours, 40 minutes Bad (down since 2023-11-24 15:52:33 UTC)
Tags:risepro RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-23n/aexe 99c7f829c90f7086b2092834ebe55a66b442bda9edd63b3ee553a70caf9993dcn/a 
2023-11-14n/aexe 5f9b962629b3eabbf190c2e0982062e3d795261cc209477e88f1d8c6ba016b08n/a RiseProStealer
2023-11-14n/aexe 9713f8c775f3ad83ffbb0987c83f7dc5bbc8646290c4a84c77e225d1d486969cn/a 
2023-11-07n/aexe a831bdc4cc298ed6563d6b3c1b0124dd4efdb71fc00af3f0a4894c1dd334350fVirustotal results 72.22%RisePro