URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.9/nokia/lamp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3154691
URL: http://31.41.244.9/nokia/lamp.exe
URL Status:Offline
Host: 31.41.244.9
Date added:2024-09-03 13:53:06 UTC
Last online:2024-09-06 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-03 13:54:10 UTC to dl{at}redbytes[dot]ru)
Takedown time:3 days, 2 hours, 57 minutes Bad (down since 2024-09-06 16:51:55 UTC)
Tags:dropped-by-PrivateLoader exe MarsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-06n/aexe ab5f78eaccc4a0f86106c547f828c2da8bd554a855deda50074c8a3cd003513aVirustotal results 49.33%MarsStealer
2024-09-06n/aexe f0947eaff9837140af164952d5ff422e3f9e35cea5c85a67709fb97638d03f12Virustotal results 39.19%MarsStealer
2024-09-06n/aexe 23de941b07e247e342a4828471f23379f7df9e8e0a3361bd5f4ba50bcc612f7aVirustotal results 41.89%MarsStealer
2024-09-05n/aexe cc14d5d1ce4419c815ddf483fe5bd0f1fe7320acfdf9c63b8241a94849d64289Virustotal results 41.33%MarsStealer
2024-09-05n/aexe 7af1ac95d468a1b0d9dfb2dbe0dba8b3aca9a09e2620a0ec35dc087f829f9401Virustotal results 41.33%MarsStealer
2024-09-05n/aexe 1bef9ae988709164b0b1daa7d266dcc465dce71ff214bba4cbb4fd81f6a27fdbVirustotal results 41.33%MarsStealer
2024-09-05n/aexe 87e8d060ce31afeea5aefceeb490b3bfa1dfbee9d408b5ac15306f9cb8caef01Virustotal results 41.33%MarsStealer
2024-09-05n/aexe 488a3eb3efaf19a0eee8131c369c47d7efd0a7e33bbf2262173a61438b471b9fVirustotal results 41.89%MarsStealer
2024-09-05n/aexe 127ebf4bdd96892ffb0c5a05c32d20a12c0d49bf910fdef8eb8e299b1f7eef21Virustotal results 41.89%MarsStealer
2024-09-05n/aexe 4905fe5b982d05ade3542668828b39a4b7ed0ec895c86b327f9881326a6d1476Virustotal results 41.33%MarsStealer
2024-09-04n/aexe c7fa00237593e4b477ecd0d4967b1116205019b91a515698f8570c857e60ab08Virustotal results 41.89%MarsStealer
2024-09-04n/aexe 59e112f9587c45ba95f90fab792996c8efba7c51832f80136060984156afe1dfVirustotal results 41.33%MarsStealer
2024-09-04n/aexe b250877cdcc29acd15fff50564c19af7e22e0a6b096c095a8773e2649047dba2Virustotal results 41.33%MarsStealer
2024-09-03n/aexe 313ae1956a2f0e533c068e8bd52fba7aabddb99001aec927e04bb277d584d178Virustotal results 41.89%MarsStealer
2024-09-03n/aexe 8e84c53178f9724d608c00a624e3efa68492d9269949a98eda8d5687c9c5cb36Virustotal results 42.67%MarsStealer