URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.47.93:30753/theme/levan.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2773500
URL: http://147.45.47.93:30753/theme/levan.exe
URL Status:Offline
Host: 147.45.47.93
Date added:2024-03-01 13:23:06 UTC
Last online:2024-03-01 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-01 13:24:05 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:8 hours, 10 minutes Good (down since 2024-03-01 21:34:29 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-01n/aexe b6ce98444f6fd7e17f6234a845b5a3ff7ab9929c618bd0eab15332e095be2412n/a 
2024-03-01n/aexe 000acab5b32031728a99c53f23faa07a9b1290ea9d9c3009891dfc292579a1ffn/a 
2024-03-01n/aexe ac444b8af1c1fc96f860ff44e874abf8220f983ce7627273927a67ada75c3ec5n/a 
2024-03-01n/aexe 52b2a7bd587134009aef8c3583f968ecbc204155798f6ce8f7b96fc53398dbcbn/a 
2024-03-01n/aexe 1860899f5ad61f4acb973f7b18ee936f9bd63e04fc5861a703bcc245349b1662Virustotal results 56.94%RiseProStealer
2024-03-01n/aexe 00d4a47b9f2836ad7a5ca7872425246e8b652b40ba1ed8367a7813014717fc5en/aRiseProStealer
2024-03-01n/aexe a7154d914f7685b479455002be4ef4940300850d7753e8993c3eef7355b03708n/a 
2024-03-01n/aexe acbf0cab6e951e01a72db59b8d62a27b4aad9f2455b7a3e2d314edcafeedc7dfn/aRiseProStealer