URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.46/kniga/demon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2809669
URL: http://185.215.113.46/kniga/demon.exe
URL Status:Offline
Host: 185.215.113.46
Date added:2024-04-12 01:15:07 UTC
Last online:2024-04-13 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-04-12 01:16:05 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:1 day, 12 hours, 1 minutes Poor (down since 2024-04-13 13:17:14 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-13n/aexe d74a5f1212ec46a6dda8e0330cdd3f6b9e642b33e6280c715eb2ca92b02b0ca6Virustotal results 34.78%RiseProStealer
2024-04-13n/aexe 1bc6db8be3cb8b88e467cdb7c06f6d29f2895bf06a472de3fcd4e10a2d5e9395Virustotal results 35.71% RiseProStealer
2024-04-13n/aexe ba17ee15f6709ac644e8eadcf9b673c05ea94c1a0f179007fd3e795a0faf3f84Virustotal results 37.14% RiseProStealer
2024-04-13n/aexe f7d108ad3920782589d80b88f8665880dad20f06e363344ecf5f6474f87b41d2Virustotal results 39.13% RiseProStealer
2024-04-12n/aexe ea2578a4f65fc0e45e70e50df45abd884684900882ddc90fa7eace9233666f77Virustotal results 39.13% RiseProStealer
2024-04-12n/aexe 214262bca02d40e14df803ae7ae69d840a4cac16a324366488d3c3df078de291Virustotal results 42.86%RiseProStealer
2024-04-12n/aexe ccaf556566ebaa23c2390b91bc0bfb5c8dc976535768e8bdd750f250aed4ad16Virustotal results 39.06% RiseProStealer
2024-04-12n/aexe 37db2e65cd45407a451681695cbc760b2c49638107164681b2d808b459d95b79n/a RiseProStealer
2024-04-12n/aexe 2233435df18c0f6b61be3f71430cd37cd965e86bee00d0673cc51f890c66b7e8Virustotal results 38.57% RiseProStealer
2024-04-12n/aexe b322879460e7894c441b9a3da703dfb4d8b2e975a33a4e4eee06940251c68e1fVirustotal results 42.03% RiseProStealer
2024-04-12n/aexe cb03ab524875b97a169e416c8c4fadc718ea1baeb726ef723d9fb0f1d13211bdn/aRiseProStealer