URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/prog/66bddfc358668_stealc.exe#space which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3114094
URL: http://147.45.44.104/prog/66bddfc358668_stealc.exe#space
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-18 11:19:05 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-18 11:20:14 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:2 months, 5 days, 6 hours, 24 minutes Bad (down since 2024-10-22 17:44:19 UTC)
Tags:dropped-by-PrivateLoader exe MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-20n/aexe cae267b73e54cb460254dd0a89a2de9a37bbb82eeba92aa6fbb26439a5d37776Virustotal results 44.00% MarsStealer
2024-08-19n/aexe 6c699ebf58c6f9d16b8bd1e0d00a051101977d6cf9ba580876abbb95a50d1f92Virustotal results 24.00%Stealc
2024-08-18n/aexe a96b3ddd991bc4a88831685ef44cbd4ad7945a4afc3a028f42812f269d513674Virustotal results 26.67%MarsStealer
2024-08-18n/aexe 74bb42b328c2406d12a63803df91307ab50c2c8bd2376de2848fc40680acf60an/aStealc