URLhaus Database

You are currently viewing the URLhaus database entry for http://109.107.182.3/hugo/rest.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2743103
URL: http://109.107.182.3/hugo/rest.exe
URL Status:Offline
Host: 109.107.182.3
Date added:2023-12-21 16:14:10 UTC
Last online:2024-01-11 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-12-21 16:15:10 UTC to abuse{at}altawk[dot]net)
Takedown time:20 days, 9 hours, 30 minutes Bad (down since 2024-01-11 01:45:31 UTC)
Tags:dropped-by-PrivateLoader risepro RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-25n/aexe 81e0f965f92b1b5ab9e12f818e2751bde8b8119f6a83fa84035434f38920c91cn/a RiseProStealer
2023-12-25n/aexe 2f0838c4b1783d79460aabf075c8b0b62838afa656b3433389feb76ce9dc2921n/a RiseProStealer
2023-12-25n/aexe c89b0dac82f285eea5bfe75b3e61635a53bba4810c73b6aaf7e53ce3a8764a89n/a 
2023-12-25n/aexe e201a7d60c5939a394c0dafc2402027fb60e43f0bd85309966f144d9c17a310en/a 
2023-12-24n/aexe 442346a2a4bd1a7f44bb8216a880f96b981217ada652ec2aa8520e586dd63bfbn/aRiseProStealer
2023-12-24n/aexe e3bbc860546b1786665d1784b0f0811c3d73dae63afca30759d45c3e22f3d5b4n/aRiseProStealer
2023-12-24n/aexe 6e766dfc3aa18732e8a511e0753cf38d055310a6128d2b59240dc8ffcdb62230n/aRiseProStealer
2023-12-23n/aexe 96ab6e3e69f401860e0f6891ea6fc471a3f3d36b50bf3c468aa303b595cbbcb5n/a RiseProStealer
2023-12-21n/aexe 4c944e0a51e946066b93b760fef883d0b6bd62c474e95df8a80e0d72265e4e10Virustotal results 72.22% RisePro