URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.77.80/netu/lana.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2877166
URL: http://77.91.77.80/netu/lana.exe
URL Status:Offline
Host: 77.91.77.80
Date added:2024-06-06 12:44:13 UTC
Last online:2024-06-08 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-06-06 12:45:10 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:2 days, 5 hours, 40 minutes Poor (down since 2024-06-08 18:25:57 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-06-08n/aexe 62faa83fc801603cc5c4704695433724f2e564fc5d713c14fc72d7f1130c7dd8Virustotal results 59.15% RiseProStealer
2024-06-08n/aexe 07b30fdbba6bacfaac454f1288e6fcdc0d8aae3f0d0cabba177100e7fb44400an/a RiseProStealer
2024-06-07n/aexe 05d9ca894b9189827f67ec6dfa62c4db1becd8cf0831db96e198400b7cf101fen/a RiseProStealer
2024-06-07n/aexe f1182038df3fbf718a3d51b0436fcfdcae3d4cadfd4c1641e3ed5c877a9e306fn/a RiseProStealer
2024-06-07n/aexe 8f5caf044dd5d81e06d806e4148720ca2b11b48e3f67bfc449b973d6737f0e32n/a RiseProStealer
2024-06-06n/aexe 553c97f29ee95a6379a5148bb3ef12e65e38850784e21f388e63cc1d22615dcfVirustotal results 54.17% RiseProStealer
2024-06-06n/aexe c172a372e0e4441eb78f2f0c30df809931bc0c8faffe2503642154da71fc85daVirustotal results 60.27%RiseProStealer
2024-06-06n/aexe e096aa948e544478d88cba58ec93009e3622a0cf1e2893ab981657898b3bf7d0n/aRiseProStealer