URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.13/lava/ramos.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3099835
URL: http://185.215.113.13/lava/ramos.exe
URL Status:Offline
Host: 185.215.113.13
Date added:2024-08-10 14:20:13 UTC
Last online:2024-08-13 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-08-10 14:21:07 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:3 days, 3 hours, 51 minutes Bad (down since 2024-08-13 18:12:07 UTC)
Tags:Amadey exe MarsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-13n/aexe 9ae91e0bb30f86d225265b6ab0c91d845e7db03635d108cdf05f88c6647d5066Virustotal results 28.00% MarsStealer
2024-08-13n/aexe 5f969cdb5dd215f67b7668507b227129f1a5699bc2999d4ebf049bda5a825f52Virustotal results 43.66% MarsStealer
2024-08-13n/aexe 57de3a0c6e8311ef1ef35855355abebf5080be5dd2d2051eadb0f204e58d547bVirustotal results 40.00% 
2024-08-13n/aexe 596b1a907c41a88cab3d66f65e971d5d8e35b0957b673f23f8b35aaa2eb84703Virustotal results 39.19% 
2024-08-13n/aexe 02b1ede9f8dcb150d797fb6e6bcc1420e91b565b80e14f0bf5a1c37324b511baVirustotal results 36.49% 
2024-08-12n/aexe ac5951159e92d5939a3427c00d0ccfb8e3a801a7e319c5e4efebdc1dfc04114cVirustotal results 35.14% MarsStealer
2024-08-10n/aexe 7e1aef3668f83b29cacc1ec2240611324de5edb51f6a32ac0df5b7cdd26684ffVirustotal results 54.67% 
2024-08-10n/aexe 3ad67f5c98e35513e0b7e50d3957f5665d0d807a167b5318b22e7137c38c377dVirustotal results 54.05%Amadey