URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.19/shama/leon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3110404
URL: http://185.215.113.19/shama/leon.exe
URL Status:Offline
Host: 185.215.113.19
Date added:2024-08-16 14:54:05 UTC
Last online:2024-08-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-08-16 14:55:08 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:20 hours, 13 minutes Good (down since 2024-08-17 11:08:56 UTC)
Tags:Amadey MarsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-17n/aexe 60dc0a2c710d9a544cca162fde3721ff442d1670c3ca3e840ebd0ca44befa6f8Virustotal results 53.62% Amadey
2024-08-17n/aexe 2f7e7ee507e2528bbe2e40d9c4f457c88c7470e24c3e0004f7b80d606b0b15e2Virustotal results 49.33% Amadey
2024-08-17n/aexe 7a951f49a26850aff2a7488cdc59fc2efd7ad96f0d554fdaa2077da5114bb282Virustotal results 50.67% Amadey
2024-08-17n/aexe 6c9ceed93757cb48ec7f85f483cd906fb9a24e4e394c84f130ba07a23724c990Virustotal results 52.00% Amadey
2024-08-17n/aexe 15310086db4e19ecf15468ac16241539cfd1378eb762b7f640b213ce066eef7fVirustotal results 49.33% Amadey
2024-08-16n/aexe 911dc85d7fd3d35fba06bf5a45c2580e1f6b369825691e8bcf63cd8f2021d2c5Virustotal results 50.00% Amadey
2024-08-16n/aexe c24565a0dea08f0b17f554aad25b25d041269170b7ca37d329181722a51910d4Virustotal results 40.54% 
2024-08-16n/aexe f3a96356eb1c36be6d3197cc2d2016527feea33a2fe0296362c0c67260009e65Virustotal results 33.78% 
2024-08-16n/aexe da047906177d92e112fbedc93b82fabe3271c292d9cb200b46a57155681d25aaVirustotal results 30.16% MarsStealer
2024-08-16n/aexe 7446880cea7ad697bdd47556774a7737224ceaeaf32622fe2b04b5d98c3b9e37Virustotal results 34.67% MarsStealer
2024-08-16n/aexe f8345c3d251b9ff3b2c57306ef636a38329e2d8567e3161598f0f4900c1980faVirustotal results 31.94% MarsStealer
2024-08-16n/aexe 583f87e11641d82473a7f6425404be87262aed79ddbca617922531ce52758b9dVirustotal results 32.43% MarsStealer
2024-08-16n/aexe ccd9eac491d3058e1095d871f954a155e881e47444847968900cae08f38f1f27Virustotal results 33.33% MarsStealer