URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.11/guba/rama.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3114286
URL: http://31.41.244.11/guba/rama.exe
URL Status:Offline
Host: 31.41.244.11
Date added:2024-08-18 13:14:08 UTC
Last online:2024-08-21 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-08-18 13:15:13 UTC to dl{at}redbytes[dot]ru)
Takedown time:2 days, 21 hours, 11 minutes Poor (down since 2024-08-21 10:26:13 UTC)
Tags:Amadey exe MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-21n/aexe adc570c21dfdc38b2b30dfa98cbd8fff624f5a83397e9199189b2182405a9535Virustotal results 37.33%Stealc
2024-08-21n/aexe 12847c870546d30d8992c191775c0e2ce051c7536edb0c9aacc86eecef2e1179Virustotal results 38.67%Stealc
2024-08-21n/aexe 57b97773593b3b07fc9607580db07bcc087b12859609cef3935cd7d933257ec2Virustotal results 36.00%MarsStealer
2024-08-21n/aexe a3a42db7a3e218aa6e20646efe0998a04da8580b448376c9f2d097479dded0e4Virustotal results 36.00% MarsStealer
2024-08-20n/aexe ead935f1295b51a63a66d2978ad3c185776e72ee57191694f4b6dcdba2db80e6Virustotal results 36.00%MarsStealer
2024-08-20n/aexe 74adc4039c75425ad6a2b19b4ab6ac460d9a21f30ae71bb71408b8f530907c9bVirustotal results 39.19%MarsStealer
2024-08-20n/aexe 8477d03a892b439f9032134b8f218c985ce81547a7179b49fc773fa4555498e7Virustotal results 37.33%MarsStealer
2024-08-20n/aexe 77193fa24e31ebe1e65ee1fab3fa709b09fd3fca7264e5bd67416560c447a765Virustotal results 55.41% Amadey
2024-08-20n/aexe d80c8b4507d2bdb403387a86a6483f9c1a656ada581db1e5a00ac9a011840bedVirustotal results 55.41% Amadey
2024-08-20n/aexe 676d20b3f13b707d53a195cf4d908889af1c0cb9abcaef264c8c58134cfbede1Virustotal results 56.00% Amadey
2024-08-20n/aexe 3a504dc5d0fc927ffbf9509ff9e9eb8bd812aa6724630a88d47e57b1fe29aa73Virustotal results 53.33% Amadey
2024-08-20n/aexe 29f70d7977e1f899dea294698fd8a5b4643fc59c33096b7ca4913cc8d243281fVirustotal results 57.33% Amadey
2024-08-20n/aexe eae0d84af32d23a0fb57fe9e0b3ab4dc6ca181d8da265dcc7bcd2baea45ee8b8Virustotal results 57.33% Amadey
2024-08-20n/aexe 607ea83486ccf97cc49542c3a193f66bc6bbe32512f80ca109aed86960119f2dVirustotal results 54.67% Amadey
2024-08-20n/aexe e8f71cbcf6e0de49306f7abb28dd2d91546f4866fce7107f469e5a286f2e142aVirustotal results 56.00% Amadey
2024-08-20n/aexe 7c17e2a16afd42e8ec40cae522b5bcfffc30ac9d82414860051690d79f803601Virustotal results 56.00% Amadey
2024-08-19n/aexe aedb7fe96ea5451ba7dd11d3ec6d591261206da8cdd8ea4460fa130f75944eddVirustotal results 56.00% Amadey
2024-08-19n/aexe 129366676ec84c8b80324b807e321508fdd4c1b049c7f1ecd7bcc286a59c7b2dVirustotal results 55.41% Amadey
2024-08-19n/aexe 146ac6bf1bfde8e2da24dcdab4117824e3a773686f67cc88f3ac47090bf37b4eVirustotal results 56.00% Amadey
2024-08-19n/aexe b6fb18598d39f74b07a44ffb01d9456402ab8c074f00e01390760f66add2f725Virustotal results 56.76% Amadey
2024-08-19n/aexe e5aad5f9dd3262f05fd44393a81a7a0a6dfc39097e10a5db360235de51999845Virustotal results 56.52% Amadey
2024-08-19n/aexe d5ff1bf0b5737c4d67cf5b49c1f99def73fb469e7e67a1859746e346759b4b84Virustotal results 53.33%Amadey
2024-08-19n/aexe 63eb5f8548a6df45875a87f6a9f79402e93a5d79cdbb918bc48af02f022e2775Virustotal results 55.41% Amadey
2024-08-19n/aexe 4465411f981d1c9161d3f5c9119ba27fa3d606188afafb67dc7561e423a14221Virustotal results 59.46% Amadey
2024-08-19n/aexe 57eb081f441d1d4ff2c0cf98bc0be187fd4c16f8b106fc814585542121b6b6afVirustotal results 57.33% Amadey
2024-08-19n/aexe ea6bafdd17dfdb867c18e1375c2c7e9b1fa3b6edb5155b6e88758e94aaa367c5Virustotal results 58.11% Amadey
2024-08-19n/aexe 270ead3dd3ce3e7e9f2d6882e81ac4e828d421f4c5824951a6756583ed185af2Virustotal results 56.00% Amadey
2024-08-19n/aexe b06858d69a4fee57203e65fb8426737f4d29bd42792c4653ec32c6b41840e0c7Virustotal results 53.33% Amadey
2024-08-19n/aexe 15efcb38c675d5fdf7878c390544393f462b29d46e8c8483bb748ae6561d4e76Virustotal results 56.76% Amadey
2024-08-19n/aexe a840d5528122d46386909e7998b18d963b0d02a68a5de2ceb9cee1dc427ba50dVirustotal results 53.33% Amadey
2024-08-19n/aexe d878030f234f47920ee616a7e8b6a888cb5fc7d6495e8462fa4ea1c225de2451Virustotal results 54.67% Amadey
2024-08-18n/aexe 5f28d9278ff003990202cef9ac9505c49e526a3208f6ad38ba59190a3b57d14bVirustotal results 54.67% Amadey
2024-08-18n/aexe 7b53c4e72addc4ce463a871011c8603aa416152fe8ce40d74516130437830ea7Virustotal results 54.67% Amadey
2024-08-18n/aexe 20f8a273a27325a7268632c1037d019b9d7a22a24526b30d50cb283b4014f480n/a Amadey
2024-08-18n/aexe 917f617aebc0d82d801c0ad0a0ba14e6d8a7c67b62db883a4c12bbe833a28561Virustotal results 56.00% Amadey
2024-08-18n/aexe 40cd8d9b6df941a90d60c7e00b6f2dbb70588ea0a3684fb39a60c393f1314afbVirustotal results 52.00% Amadey
2024-08-18n/aexe ab784e890cd75d28bbafa92580d1bd78e425eae49a189e93fdeeb41103e28ad5Virustotal results 55.41% Amadey
2024-08-18n/aexe 10afb5f99e9f494907a0b47823e69573301e7715ab389457bdcd391d8e9cf090Virustotal results 53.33%Amadey