URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.77.80/tonik/voda.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2945045
URL: http://77.91.77.80/tonik/voda.exe
URL Status:Offline
Host: 77.91.77.80
Date added:2024-07-09 01:14:07 UTC
Last online:2024-07-12 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-09 01:15:22 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:3 days, 11 hours, 31 minutes Bad (down since 2024-07-12 12:46:25 UTC)
Tags:dropped-by-PrivateLoader Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-11n/aexe 55181aa3af9da0fc833f73d53694e9bc6c8c0df77126a86f9e9d92e6c34221c7Virustotal results 46.58%Stealc
2024-07-11n/aexe 59d115c4f1a0035301f09d9697f988c7f667d0131582dfa7a28990fc02baa086Virustotal results 45.21%Stealc
2024-07-11n/aexe 7614f3191e218056402bb21b5349f37435d986f7d81954555d6b776df808b18eVirustotal results 44.59%Stealc
2024-07-10n/aexe da68eede5f489072a8f0e34579d75ccefa0adefa2363cb6a2923c09f3f3d2b0bVirustotal results 44.44%Stealc
2024-07-10n/aexe f6bd9644cb568ce7f7ca4bf2dacf352472b36d656735c1eafe97191a5dac6c7cVirustotal results 47.30%Stealc
2024-07-10n/aexe 9be8bf8f01c3b2f8ae295f1fc9be5fe5e05596a80be603d0de23e9a6ddbb5a04Virustotal results 50.00%Stealc
2024-07-10n/aexe 4f8c4c304d73e6e2d3d11708c57b158e648bd79132f0a973520dc14f9e3e2e01Virustotal results 47.30%Stealc
2024-07-10n/aexe dde5350c96db38ab11703a77e742e252487c4cbc3321f95cc73ff3801442f1b9Virustotal results 45.21%Stealc
2024-07-09n/aexe d87490fe72c11df8476414b03d613fff99a59894193c25121bde71c745b91c5dVirustotal results 44.59%Stealc
2024-07-09n/aexe 1013ef0d12658680241090322d56cbfd6ad665fd922049180184c3fef077a506Virustotal results 47.30%Stealc
2024-07-09n/aexe 546b5457cd26c9230fc49a456197aeeb761241adc2dd2774c37b1d3189968cb9Virustotal results 46.48%Stealc
2024-07-09n/aexe 77e9b3740b0e2fd375cd1981ce2ad2ece335200794fa7eb92d4befee2094b9ceVirustotal results 45.95%Stealc
2024-07-09n/aexe 42925f90758bbcac4f02d0f58e671ef5d071e1f528a3aa2b4cfa7715da9ff215Virustotal results 45.07%Stealc
2024-07-09n/aexe c11e7133c481e34c3ac90d33416e85490b4e4b3b2af782fae22138298bb0e404Virustotal results 56.76%Stealc
2024-07-09n/aexe 25d515f52e58c10727895f1ee1a269998e37d3b4308e6ac6f1419186c30290a9Virustotal results 46.48%Stealc