URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.77.80/devka/rama.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2941921
URL: http://77.91.77.80/devka/rama.exe
URL Status:Offline
Host: 77.91.77.80
Date added:2024-07-07 04:49:08 UTC
Last online:2024-07-08 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-07 04:50:22 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:1 day, 18 hours, 0 minutes Poor (down since 2024-07-08 22:50:32 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-08n/aexe 9e12b808314ab31153be5ca2472dde413e0f3d8c0fdb038261397d7a4881b739Virustotal results 42.03%Stealc
2024-07-08n/aexe 7378f4059b53f7da3e135c76ce4d6d6dc3af8106f510f128a77c5688f958a803Virustotal results 44.59%Stealc
2024-07-08n/aexe 3729d0a825685cb3f1d22da6a41ad8f23ea9a44539f9e9f6d2bb9fcef1723013Virustotal results 60.81%Stealc
2024-07-08n/aexe 3781240686f18f44cfb8397dfe462c164a00f0c4b08177b468129bc8c41a1f22Virustotal results 61.64%Stealc
2024-07-08n/aexe 5986af20c5aa3b134f85fc08b1da2e3851f644bb9c7b8774377599e444dbcc26Virustotal results 58.90%Stealc
2024-07-08n/aexe 1ad057f20760236870be5f5a81fe789f0d33184371426bf5d278f64248ae5258Virustotal results 58.90%Stealc
2024-07-07n/aexe c9155f89c82b6043a474addbc6afd42ea2fd30c242fcb99266fbf0b6b94ec4edVirustotal results 58.90%Stealc
2024-07-07n/aexe 43fefcf79068cf7cb0b45426f60c89eb92943c652be486e9b9ecd7d5b92ce282Virustotal results 55.41%MarsStealer
2024-07-07n/aexe a8b6bae3666f4750edbc70c8ec4022adfd63c198c250a6493abf073fa0396da7Virustotal results 59.46%Stealc
2024-07-07n/aexe e4725ec14fd7c7d20a53e85e49301255caf470080352dab75856cb6c046de37dVirustotal results 64.38%Stealc
2024-07-07n/aexe c5bd507d607a85292dbd26e9ef87924d525680eb08eaf489f5dabb46a15a8ce1Virustotal results 58.11%Stealc
2024-07-07n/aexe 4db680528104c9edafe50c7da30e3e033ca0e36c3668ebf591863a9030f5aa01Virustotal results 58.11%Stealc