URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.96.7/rumba/buben.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2834556
URL: http://5.42.96.7/rumba/buben.exe
URL Status:Offline
Host: 5.42.96.7
Date added:2024-05-01 22:52:07 UTC
Last online:2024-05-02 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-05-01 22:53:05 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:1 day, 1 hours, 2 minutes Poor (down since 2024-05-02 23:55:31 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-02n/aexe fc0412dca9987c1f82d92243e157e0d54a33ef1904ab32696d5cf686ed774d34Virustotal results 47.22% RiseProStealer
2024-05-02n/aexe ffc2f5a450d08085a70f1c93187b4d23a807287052954ebe333aff74a738a0ffVirustotal results 46.48% RiseProStealer
2024-05-02n/aexe 1ed1aeb31961f6f3e8b184e8dc32f16c7445dcc3f72d3ba7409f0e8c9073f73eVirustotal results 46.38% RiseProStealer
2024-05-02n/aexe 0b8fda39a466ec5c8752213ff51bc9a500712fc2434392def0a1436345704e21Virustotal results 45.83% RiseProStealer
2024-05-02n/aexe 360f95cde09686042a0c4264d5ffc9e2418faeb68b2a8be111942b4d540eaee2Virustotal results 44.44% RiseProStealer
2024-05-02n/aexe 7cf9c3f092afee2ba38d660aa59e263b329ecc899e583660cd3b59fcd29f9a02Virustotal results 37.50%RiseProStealer
2024-05-01n/aexe 8f2d99ca04db3fc50810158be6f60f4df8df819dd30227d58287f71b220fbfb8Virustotal results 37.50%RiseProStealer