URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.96.7/doka/candy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2841772
URL: http://5.42.96.7/doka/candy.exe
URL Status:Offline
Host: 5.42.96.7
Date added:2024-05-07 14:33:11 UTC
Last online:2024-05-08 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-05-07 14:34:18 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:1 day, 3 hours, 42 minutes Poor (down since 2024-05-08 18:16:25 UTC)
Tags:Amadey dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-08n/aexe 9ad61eec5fc430a1fff1a06b746b726fd2b9beccb20c6d6d659feab4fc339b96Virustotal results 50.79% RiseProStealer
2024-05-08n/aexe d8eaef16d61598442f40a983786ba614dd3945aa9afa65634a49acf56c69e761n/a RiseProStealer
2024-05-08n/aexe ed0162bba102fa5e5f3d12cd93e008b52786bf78b2178bb68f904fafcf01354eVirustotal results 47.95% RiseProStealer
2024-05-08n/aexe 3253f08de729c361ae165dc234e011d4c3d373b3673bf44041d1c485c99b97a3Virustotal results 48.57% RiseProStealer
2024-05-08n/aexe 2c8ade2f3d623f25c7844ef7598f069e7d7cac6039b53a6dff0858415bebe16dVirustotal results 48.61% RiseProStealer
2024-05-07n/aexe 765a42bc7cff6c294e138d70aa29cf5e2eda15cee16f9ffee7aefea5eac43708Virustotal results 47.95%RiseProStealer
2024-05-07n/aexe 211dd4d658821750062e7b7189e0a3cde4f081e38e7a325c8f8f23bbd6d10b93Virustotal results 50.00%Amadey
2024-05-07n/aexe 5ea0356d96f0fc808a2568c034c55c24fa642c6c5fa503c7d2172ce3ba7cb335n/aRiseProStealer