URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.96.145/work/gena.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2854775
URL: http://5.42.96.145/work/gena.exe
URL Status:Offline
Host: 5.42.96.145
Date added:2024-05-18 20:33:13 UTC
Last online:2024-05-27 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-05-18 20:34:10 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:8 days, 5 hours, 29 minutes Bad (down since 2024-05-27 02:04:04 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-21n/aexe 5973aaacf23b49570c3785da528cc63ade194b602d9699a1fe3c6536ef367d45n/a RiseProStealer
2024-05-21n/aexe d5f38d8cf7a45b138fcd938604ea0a3a37c26a66b5de2a9162d2ddec043c7d74Virustotal results 41.89% RiseProStealer
2024-05-21n/aexe a59b2a8820e992d55b3ca8b289e26b0c6e66e75146df9565ff1ffcf8ccb47f3cVirustotal results 39.19% RiseProStealer
2024-05-21n/aexe 1fe356dc287cdb894099f7b061f0fcd28c9d1a5147ba480b8c3ffe1e1d1654f5Virustotal results 54.05% RiseProStealer
2024-05-20n/aexe 55056d3db5ad347efbd66be2fdc03fa2f19e1d900faf82e940271fe7b525fe5fVirustotal results 54.05% RiseProStealer
2024-05-20n/aexe 4083d671daac2786934c6872d4297a14103a25162075bda94d656221920d951cVirustotal results 54.05% RiseProStealer
2024-05-20n/aexe c0b1d891bdc272599578a5b0d8fcee9ed3b58caa2245c1553ba155803f213900Virustotal results 52.11% RiseProStealer
2024-05-20n/aexe 264b38772eaed123b2529ac263787d47dd1191911c7a711794c383f91df6a46aVirustotal results 53.42% RiseProStealer
2024-05-20n/aexe 789990f90c04a0ec2e11124e357f5ab8414b3706c357ce769d7cf1f603189081Virustotal results 54.17% RiseProStealer
2024-05-20n/aexe af4d563a9c06babef7e3aa827318d4bdac76fde24a44d40fa3574f94143430dcn/a RiseProStealer
2024-05-19n/aexe 565bb4ee35dcec8571a2ba642377456ea75d4ac3db5ac611019f27307299ead5Virustotal results 56.16% RiseProStealer
2024-05-19n/aexe 9268667e2bc9209bc9748d894f66b8916a0463d0ef8ec11381108cb3debc8e8cVirustotal results 52.78% RiseProStealer
2024-05-19n/aexe 071cff793083aeca5e0870d707c99ff529d48a99af459cb74c7022bbf50da8efVirustotal results 53.42% RiseProStealer
2024-05-19n/aexe 9691018c95ca16ed9ca112b740d173c2cbae94a019298390ae0c451e19d29510Virustotal results 53.42% RiseProStealer
2024-05-19n/aexe b503362c1b99d562a9c3b47c1f8de683ab1a654821d20d44c4bc58e1f7345944Virustotal results 54.79% RiseProStealer
2024-05-18n/aexe 540b9ebcebcf6cda9d21153edcecec883f108442422def941aacf3d8e735537bn/aRiseProStealer