URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.10/guba/rama.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3114285
URL: http://31.41.244.10/guba/rama.exe
URL Status:Offline
Host: 31.41.244.10
Date added:2024-08-18 13:14:06 UTC
Last online:2024-08-21 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-08-18 13:15:12 UTC to dl{at}redbytes[dot]ru)
Takedown time:2 days, 22 hours, 30 minutes Poor (down since 2024-08-21 11:45:59 UTC)
Tags:Amadey exe MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-21n/aexe adc570c21dfdc38b2b30dfa98cbd8fff624f5a83397e9199189b2182405a9535Virustotal results 37.33%Stealc
2024-08-21n/aexe 12847c870546d30d8992c191775c0e2ce051c7536edb0c9aacc86eecef2e1179Virustotal results 37.33%Stealc
2024-08-21n/aexe 57b97773593b3b07fc9607580db07bcc087b12859609cef3935cd7d933257ec2Virustotal results 36.00%MarsStealer
2024-08-21n/aexe a3a42db7a3e218aa6e20646efe0998a04da8580b448376c9f2d097479dded0e4Virustotal results 36.00% MarsStealer
2024-08-20n/aexe ead935f1295b51a63a66d2978ad3c185776e72ee57191694f4b6dcdba2db80e6Virustotal results 36.00%MarsStealer
2024-08-20n/aexe ff1820e68a7067ef6ad78ea9c19b929eb52729f85e349f75e226615ea72532f2Virustotal results 37.84%MarsStealer
2024-08-20n/aexe 74adc4039c75425ad6a2b19b4ab6ac460d9a21f30ae71bb71408b8f530907c9bVirustotal results 40.28%MarsStealer
2024-08-20n/aexe 8477d03a892b439f9032134b8f218c985ce81547a7179b49fc773fa4555498e7Virustotal results 37.33%MarsStealer
2024-08-20n/aexe 3f41bd4a137ade5d875f7a46fc2962511642cc4bffef7dfdb1646f30fa8bf229Virustotal results 53.33% Amadey
2024-08-20n/aexe d80c8b4507d2bdb403387a86a6483f9c1a656ada581db1e5a00ac9a011840bedVirustotal results 55.41% Amadey
2024-08-20n/aexe 676d20b3f13b707d53a195cf4d908889af1c0cb9abcaef264c8c58134cfbede1Virustotal results 56.00% Amadey
2024-08-20n/aexe 3a504dc5d0fc927ffbf9509ff9e9eb8bd812aa6724630a88d47e57b1fe29aa73Virustotal results 53.33% Amadey
2024-08-20n/aexe eae0d84af32d23a0fb57fe9e0b3ab4dc6ca181d8da265dcc7bcd2baea45ee8b8Virustotal results 57.33% Amadey
2024-08-20n/aexe 607ea83486ccf97cc49542c3a193f66bc6bbe32512f80ca109aed86960119f2dVirustotal results 54.67% Amadey
2024-08-20n/aexe e8f71cbcf6e0de49306f7abb28dd2d91546f4866fce7107f469e5a286f2e142aVirustotal results 56.00% Amadey
2024-08-19n/aexe 7ca2db4d4b8e506350a4e6a4b5aad4d0f4916cc2899db1444631cbb9cecc8f75Virustotal results 53.33% Amadey
2024-08-19n/aexe aedb7fe96ea5451ba7dd11d3ec6d591261206da8cdd8ea4460fa130f75944eddVirustotal results 56.00% Amadey
2024-08-19n/aexe 129366676ec84c8b80324b807e321508fdd4c1b049c7f1ecd7bcc286a59c7b2dVirustotal results 55.41% Amadey
2024-08-19n/aexe 146ac6bf1bfde8e2da24dcdab4117824e3a773686f67cc88f3ac47090bf37b4eVirustotal results 56.00% Amadey
2024-08-19n/aexe b6fb18598d39f74b07a44ffb01d9456402ab8c074f00e01390760f66add2f725Virustotal results 56.76% Amadey
2024-08-19n/aexe dcea76f42107adaef2d8bbe2d32bfeae8ad6b1cb94e7d94029934f20f98ba090Virustotal results 56.00% Amadey
2024-08-19n/aexe d5ff1bf0b5737c4d67cf5b49c1f99def73fb469e7e67a1859746e346759b4b84Virustotal results 53.33%Amadey
2024-08-19n/aexe 73181c643bff01c0a23ff7a31c2936defe659f74ec5c0a4c5b1535d826aa02f7Virustotal results 53.33% Amadey
2024-08-19n/aexe 63eb5f8548a6df45875a87f6a9f79402e93a5d79cdbb918bc48af02f022e2775Virustotal results 55.41% Amadey
2024-08-19n/aexe 4465411f981d1c9161d3f5c9119ba27fa3d606188afafb67dc7561e423a14221Virustotal results 59.46% Amadey
2024-08-19n/aexe 57eb081f441d1d4ff2c0cf98bc0be187fd4c16f8b106fc814585542121b6b6afVirustotal results 60.56% Amadey
2024-08-19n/aexe ea6bafdd17dfdb867c18e1375c2c7e9b1fa3b6edb5155b6e88758e94aaa367c5Virustotal results 58.11% Amadey
2024-08-19n/aexe 270ead3dd3ce3e7e9f2d6882e81ac4e828d421f4c5824951a6756583ed185af2Virustotal results 56.00% Amadey
2024-08-19n/aexe b06858d69a4fee57203e65fb8426737f4d29bd42792c4653ec32c6b41840e0c7Virustotal results 53.33% Amadey
2024-08-19n/aexe 15efcb38c675d5fdf7878c390544393f462b29d46e8c8483bb748ae6561d4e76Virustotal results 56.76% Amadey
2024-08-19n/aexe 7835a26e3f5ea565c099b426c66838dbea8642cd7dcf51fdfc260b1cd9bde4a6Virustotal results 56.00% Amadey
2024-08-19n/aexe a840d5528122d46386909e7998b18d963b0d02a68a5de2ceb9cee1dc427ba50dVirustotal results 53.33% Amadey
2024-08-19n/aexe d878030f234f47920ee616a7e8b6a888cb5fc7d6495e8462fa4ea1c225de2451Virustotal results 54.67% Amadey
2024-08-18n/aexe 5f28d9278ff003990202cef9ac9505c49e526a3208f6ad38ba59190a3b57d14bVirustotal results 54.67% Amadey
2024-08-18n/aexe 7b53c4e72addc4ce463a871011c8603aa416152fe8ce40d74516130437830ea7Virustotal results 54.67% Amadey
2024-08-18n/aexe 20f8a273a27325a7268632c1037d019b9d7a22a24526b30d50cb283b4014f480Virustotal results 54.67% Amadey
2024-08-18n/aexe 420a1ba2737e39704e52e1ea0c2494d8c232f10e2b40971923959da4708b3b0cVirustotal results 54.05%Amadey
2024-08-18n/aexe 40cd8d9b6df941a90d60c7e00b6f2dbb70588ea0a3684fb39a60c393f1314afbVirustotal results 52.00% Amadey
2024-08-18n/aexe ab784e890cd75d28bbafa92580d1bd78e425eae49a189e93fdeeb41103e28ad5Virustotal results 55.41% Amadey
2024-08-18n/aexe 10afb5f99e9f494907a0b47823e69573301e7715ab389457bdcd391d8e9cf090Virustotal results 53.33%Amadey