URLhaus Database

You are currently viewing the URLhaus database entry for http://193.233.132.139/gavno/nikto.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2827064
URL: http://193.233.132.139/gavno/nikto.exe
URL Status:Offline
Host: 193.233.132.139
Date added:2024-04-25 18:35:15 UTC
Last online:2024-04-28 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-04-25 18:36:10 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:2 days, 22 hours, 11 minutes Poor (down since 2024-04-28 16:47:55 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-28n/aexe 1f25d666bfdb68c40c8c2fe80ac1514d38d9b6a3383f7600482572afdcd2383cVirustotal results 45.83% RiseProStealer
2024-04-28n/aexe 3eac7ecf4db8932790dc10ee9d633e95292cbb3c59000c27b846d3efa7a9c92eVirustotal results 43.06% RiseProStealer
2024-04-28n/aexe ae0d929efc63331d85840148cde7ab09005a0487c231b24a9e7a480edd55820eVirustotal results 42.65% RiseProStealer
2024-04-28n/aexe e71276b925cbf25149dd49b21c708cb6f54778eea97146247541f1f2c86975a4Virustotal results 41.67% RiseProStealer
2024-04-28n/aexe ff56a63439be66d81f22c0c6b91c92e8b754b81a3a526259715fa43838202012n/a RiseProStealer
2024-04-27n/aexe d1c88d2ca36a260f973712d1acc812d0014c0abd08f5994a8e97507624a013a1Virustotal results 43.06% RiseProStealer
2024-04-27n/aexe 66be338a2b69c79988e289ea8152ac82a734af3b1b3369fc81aa6e067fbadad8Virustotal results 43.06% RiseProStealer
2024-04-26n/aexe ada1b93bcc21fe340911a68df3c5c893466e76bf65fe31342de5b9f2d7657be2Virustotal results 43.06% RiseProStealer
2024-04-26n/aexe 9889cf04ff62e8a69b2f6cc2c42385403912bdced18d9c083400401bdee3cc84Virustotal results 43.06% RiseProStealer
2024-04-26n/aexe 8e098883592e5c1f543db7874f4e128133a4c7d5d803bad85b8b1ea13b7dfbd5Virustotal results 44.44% RiseProStealer
2024-04-26n/aexe 69a1e4729179bbdefda27658d61d702d4c1fb760169fc3b1c806a4724e5e4255Virustotal results 41.67% RiseProStealer
2024-04-25n/aexe 026387aa4411dac1107e403fb44fa90c5a34ec5ab0068af13e3f8f9f0b0f46cdn/aRiseProStealer