URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.77.80/dzen/hohol.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3058171
URL: http://77.91.77.80/dzen/hohol.exe
URL Status:Offline
Host: 77.91.77.80
Date added:2024-07-21 11:44:05 UTC
Last online:2024-07-24 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-21 11:45:08 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:2 days, 13 hours, 22 minutes Poor (down since 2024-07-24 01:07:12 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-23n/aexe 10db0258fb84c3d7ee659a64eda64c552f234e7377adac19af9bb2fb117b120aVirustotal results 37.25%Stealc
2024-07-23n/aexe 9de7148d3092790bc8e26c6a047225aeaab66550e546a3fa372b50425bd76b41n/aStealc
2024-07-23n/aexe d747ab8be3ac467112c7325ba1cd57111cc080a98da6672c81be5a91dfbd9a56Virustotal results 45.95%Stealc
2024-07-23n/aexe 0c1f6f5b1b5805fad2aa86fe12b6e24be69565c46d179b5eb8ce76614f3e2993Virustotal results 44.59%Stealc
2024-07-23n/aexe c2643566b7886f6c16bc19e6eb804a7791bc713ae18b27f0d7fca938ca8f6817Virustotal results 42.25%Stealc
2024-07-23n/aexe d264838d9f1199dc54fc71623623bfcca58f05dbbfe958424c2758bc655dfcaaVirustotal results 45.95%Stealc
2024-07-23n/aexe 8e30088691e13e06713d21bc9c56c1e539eb42cb42ec9acb3de4b7243b796b12Virustotal results 44.59%Stealc
2024-07-23n/aexe a742195deed206c4ece07a4ee6f72f9ea2463ceb5ca9587f82758829c20571ccVirustotal results 48.65%Stealc
2024-07-23n/aexe 18b8662e5d0b1f00302bbe26ddb5fa099da34a0d3255180d2358d6066bb42348Virustotal results 36.49%Stealc
2024-07-22n/aexe 71fd5d7abb467458d0b731362d5f5ed722f6b94eb64e6207585db8b199bf3c3aVirustotal results 33.80%Stealc
2024-07-22n/aexe 6e5edc5f4a5030f292e9166255eb6e1fb1da3ffe9a14bd39d9b9db55fd713510Virustotal results 32.88%Stealc
2024-07-22n/aexe 00a10d07277a7230bf72e4a77a4fd0a7b7b8d031e671e16432f7838676cb2456n/aStealc
2024-07-22n/aexe 3a2d700be270e655689ab54fa1e9ac0fce79b966dc0857a2b3b8a85644c8fe35Virustotal results 53.42%Stealc
2024-07-22n/aexe 3e92cafeb19680b98ceff1ac9103d0f132b19af61aa9241ff6b59dd1bb96cffdVirustotal results 59.46%Stealc
2024-07-22n/aexe 15e918d1df17402cac720b75c85e81587d15ef620e89b639ad71085ce77ca8c8n/aStealc
2024-07-22n/aexe 9d84bd88528a492f52572cea1a2689c8c6a24a51952fefe1ab9b906a2db55851Virustotal results 57.53%Stealc
2024-07-21n/aexe 5a48f7ceeb3a0ef874ee3247079ce780b39e8af328aaa8b1e91cfed4729969a3Virustotal results 58.90%MarsStealer
2024-07-21n/aexe 1341f6c36b6bf06dd1f0d88153c8262d98fdfc5747d8996ea45959d0b475f740Virustotal results 39.44%Stealc
2024-07-21n/aexe e9e8387e07a0b20cd448abc1fb9654c2188de5e10c074e71030c8dda74e5701cVirustotal results 74.07%Stealc