URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.9/moda/crown.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3122269
URL: http://31.41.244.9/moda/crown.exe
URL Status:Offline
Host: 31.41.244.9
Date added:2024-08-22 10:46:05 UTC
Last online:2024-08-24 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-22 10:47:07 UTC to dl{at}redbytes[dot]ru)
Takedown time:2 days, 2 hours, 22 minutes Poor (down since 2024-08-24 13:09:52 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-24n/aexe abc7d305494e329e2656cc5518521e9f567943556094f44606b44c5055cbd2bdVirustotal results 37.33%MarsStealer
2024-08-24n/aexe 294d831907d2ed07abaed8823bcf39fefd0432ff3d8464711f89dfca5f297f47Virustotal results 37.33%Stealc
2024-08-23n/aexe d1de87bc5bee4f8596a7701f52102cbb932199330c00e0bda50307e9a5d66be5Virustotal results 37.84%Stealc
2024-08-23n/aexe d79dd72319dcbefd88975bebca1fc4812d066939aa69cf3f83324025354f95d7Virustotal results 36.00%Stealc
2024-08-23n/aexe a2dca9cd15d5cefcf3e45ab630696374372b0de47626146af448eb0613184495Virustotal results 37.33%Stealc
2024-08-23n/aexe a8a66f8e5c3a7d64e963ba8bcfd079e929fa407892d61ff3c8d82aa8d93a1542Virustotal results 36.49%Stealc
2024-08-23n/aexe da1ddd0279d95722b32f4930fa95ad677203f92c65d4f4bf2bbb6c0b2b7073f5Virustotal results 37.33%MarsStealer
2024-08-23n/aexe 2141d9159c4fca891bba493acba71c5973b9d554e4b0552f4a87be7f3bcd112eVirustotal results 38.67%MarsStealer
2024-08-23n/aexe 5fa9a5fa317c6f93e2aa7eba995e330d9d2b29951841f26f3a3786d35e93eedbVirustotal results 38.36%MarsStealer
2024-08-23n/aexe 45d2191202c5317d62a405852845be0c4d2084c3663f2ccfb1bea773bb9c6bc8Virustotal results 41.33%MarsStealer
2024-08-23n/aexe a462d34b1badf6633f88d2cab11db9c9aff9122c8c7dacfbeba21c4d66bc5a74Virustotal results 40.00%MarsStealer
2024-08-22n/aexe 19c61af4933da3f3acd5dbddc1623d759c2e190851ebf0da878b2cd661c414b1Virustotal results 39.19%MarsStealer
2024-08-22n/aexe 6ad985ac636b93d6c040972403b0de2f643614483a4157d897d2ca310917fd77Virustotal results 36.49%MarsStealer
2024-08-22n/aexe aaabd62bb4849ab33f6ec6dc9b09c71a198987e44ed6ca08ebba2ec5f8d56f22Virustotal results 49.33%Stealc
2024-08-22n/aexe 9c78eb276e02866cbc32f4994f500055f03977918bad1643ade8e65195ecc553Virustotal results 38.67%MarsStealer
2024-08-22n/aexe 89da0df3fd3086d1bc2e4fe5183491423a4bd9ad3badc0ac97e6a3d8088430ddVirustotal results 40.00%MarsStealer
2024-08-22n/aexe 53c21c1975b578d25f6f634ffbf374e04ec908af4813bdedc721d271f8598df9Virustotal results 37.33%MarsStealer