URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.96.52/tako/gamak.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2846091
URL: http://5.42.96.52/tako/gamak.exe
URL Status:Offline
Host: 5.42.96.52
Date added:2024-05-10 22:28:07 UTC
Last online:2024-05-11 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-05-10 22:29:05 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:14 hours, 29 minutes Good (down since 2024-05-11 12:58:28 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-11n/aexe 9daa69c49c8bab2f4546a4546ed9e96502fb3d65a15a8a913528a278753bd9e2Virustotal results 49.32%RiseProStealer
2024-05-11n/aexe 918df59053b8d75aefc87bbb6ae26af06269bdc7e972c6160d409df08d9af4a9Virustotal results 49.30% RiseProStealer
2024-05-11n/aexe 9b1f369fd5ebcafebad8549a388ba9d8448a16e72b3687708b1f61feb07136caVirustotal results 49.32% RiseProStealer
2024-05-10n/aexe c8ea649a1afc19b079103e6791de2b11d15999aba6e39714dcd9801011c759e1n/aRiseProStealer