URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.77.80/cant/tuman.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2949689
URL: http://77.91.77.80/cant/tuman.exe
URL Status:Offline
Host: 77.91.77.80
Date added:2024-07-11 11:49:07 UTC
Last online:2024-07-13 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-11 11:50:22 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:2 days, 8 hours, 0 minutes Poor (down since 2024-07-13 19:51:06 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-13n/aexe 73aa846fc6566e449ad9c89f487f74c7c51dea5c003f8a9010cc1b9b49248789Virustotal results 47.30%Stealc
2024-07-13n/aexe 110a3616523579af31689b0adb305d0dde68d103d2d836b1e1649df802dac599Virustotal results 46.58%Stealc
2024-07-13n/aexe 10cbb2a56cd1ab7bd32cae5b3c61d3a4a7277e838357db77d4b8f7c87df5a86fVirustotal results 46.58%MarsStealer
2024-07-13n/aexe b9ce9a4cbde31bbcd141e3e0136c0474f23b3008c043e365cec3926758283423Virustotal results 48.65%Stealc
2024-07-12n/aexe 1fae7a09da2d90805c3c5ddc97b91d36236171c34e79c8f3a3de945ac2ba25a2Virustotal results 44.59%Stealc
2024-07-12n/aexe 475edb8959f811cdf9b554d8707efd56906a8ff4fc2888a68d2b3a556b6e8272Virustotal results 55.41%Stealc
2024-07-12n/aexe c19e844a529bb52d59a243340243e2208ad23ca059aa6b095f555f415d22f687Virustotal results 47.30%Stealc
2024-07-12n/aexe f085c6c04bb96f24fdbf974025a25ca0baaf01093996d5b8be8f4b03045892c2Virustotal results 49.30%Stealc
2024-07-12n/aexe d25e817eee335c0f2baaf75f39e40ac410fbbfb2089d20f604718ccf053e27d4Virustotal results 47.30%MarsStealer
2024-07-12n/aexe 1b6722f558bf4483253663180682caec67066261bc0414d12d6e1622cb848d80Virustotal results 47.30%Stealc
2024-07-11n/aexe 41fe619fbe5a96e2be0cc43ca6e2ab6712b2914b5dfa08cb2ee4f5a43248bbe0Virustotal results 46.58%Stealc
2024-07-11n/aexe d81a4a8069199cb989351fb3053f47dd97027446886cb2b0044fef773749a81bVirustotal results 47.30%Stealc
2024-07-11n/aexe 460bf26fa9c9b59fe9e5bc6a83196e532ff441385f106b322431b0a6dc7787c4Virustotal results 47.30%Stealc
2024-07-11n/aexe 4a1aae8c7fac1f4e79c39b6da1b431c4d3dc25585083ac569b9943392acefb77Virustotal results 48.65%Stealc