URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.9/zoom/leto.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3129259
URL: http://31.41.244.9/zoom/leto.exe
URL Status:Offline
Host: 31.41.244.9
Date added:2024-08-26 10:35:10 UTC
Last online:2024-08-30 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-26 10:36:07 UTC to dl{at}redbytes[dot]ru)
Takedown time:4 days, 3 hours, 17 minutes Bad (down since 2024-08-30 13:53:14 UTC)
Tags:dropped-by-PrivateLoader exe MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-29n/aexe ff84c15e4a2ee9134e90d3c99eedbac7c0f3dcab32834d2bd210c54b48b421d3Virustotal results 40.00%Stealc
2024-08-29n/aexe 20feef1cd2f7bc7afa599f5e3305fc5cebe04110b5dc6e99c1844efb7b31aeeeVirustotal results 36.99%MarsStealer
2024-08-28n/aexe fc86e5bfea8a759be87dd3e752ab37158699b93d80fcae470ec2394eb1c66b37Virustotal results 37.33%MarsStealer
2024-08-28n/aexe 7f8ea1e8897f9af7a5ced22e8c6a7e07811700220ac2c3ba50375c2c4926d7e9Virustotal results 40.54%MarsStealer
2024-08-28n/aexe c39eee3fee330717d83074da5df2f9f1a5ec00c4a0fc7191462b024693b47e8aVirustotal results 40.00%MarsStealer
2024-08-27n/aexe 397431a47e9c032a13cd78446c9139696531a963d9c7f65a3a4742e82cd0cc8aVirustotal results 39.13%MarsStealer
2024-08-27n/aexe 6509ea13b16d01894b8c084fc4fd292651d1ae88a59dfc63d2f87d8dbbcc6f03Virustotal results 39.19%MarsStealer
2024-08-27n/aexe 1efb996935a283af752509705812d29a63c38146163f2ba264b494227b67454cVirustotal results 40.00%MarsStealer
2024-08-27n/aexe 38a1f1e8ee82fadbae89062ec9a37d84632fe5e6cd29e0cb6820e3d0f808f2e1Virustotal results 38.36%Stealc
2024-08-27n/aexe b22916ff9215d5a9a1ad717f20a79ab24dc4e1fa4ee95f1326bb14bcde81ea3aVirustotal results 38.67%MarsStealer
2024-08-27n/aexe 0f1b2cef6cc9ac8943bd32edd80c5e83c6d42999e0fc15eefcdb933b7d8ae304Virustotal results 40.00%MarsStealer
2024-08-26n/aexe d5bbca7e6e9ef629623a0950983a2889fe0a6025df90c94aaf3b1bb9eefc3621Virustotal results 40.00%MarsStealer
2024-08-26n/aexe 89a4db7e014bce27c792926a65b2c2ca9911cc9a12ddcf1c4767619a3f6b8b36n/aMarsStealer