URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.46/simon/gumer.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2813676
URL: http://185.215.113.46/simon/gumer.exe
URL Status:Offline
Host: 185.215.113.46
Date added:2024-04-16 04:53:05 UTC
Last online:2024-04-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-04-16 04:54:05 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:1 day, 7 hours, 32 minutes Poor (down since 2024-04-17 12:26:46 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-17n/aexe 37e389db3f9b285e00e11260c0c3656e026f0627bfbbe42b3e9e07f8899f5838Virustotal results 45.07%RiseProStealer
2024-04-17n/aexe bc8ca26c23b8985617a798af658ba9d49125f6a4a41d421c388752e1c8d3ef3cVirustotal results 47.89% RiseProStealer
2024-04-17n/aexe 80cc10923bcba090e2ef7507eb54bdc444d238ed41c7a15f42648733538ad01dVirustotal results 35.21% RiseProStealer
2024-04-16n/aexe 25f7c6fada81cf45916ee483b2b158449e7720e3901bea12fa271b78ab78b847Virustotal results 35.94% RiseProStealer
2024-04-16n/aexe 43110ac261d59fc3b2d384804952973d772979eb371465e7bd5a73acfda2024eVirustotal results 47.89% RiseProStealer
2024-04-16n/aexe 78cad7b2b9266a04953e41572162059f2df2f14691ee3310bc355cfb43dda28eVirustotal results 33.80% RiseProStealer
2024-04-16n/aexe 716ea725c37aa966089b0bf3698e318c75f0ba967824a4b35ed32328256b1aacVirustotal results 47.14% RiseProStealer
2024-04-16n/aexe f02fb0fa01761d5a093d217272d936bde478ce35b4bda9cafb0ae01e63fb5e6cVirustotal results 45.71% RiseProStealer
2024-04-16n/aexe abe47b0a9daf89fb619a25911ba9c1e2bd045aba0eb7648311814cceece54f68n/aRiseProStealer