URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.9/nexia/fugu.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3163564
URL: http://31.41.244.9/nexia/fugu.exe
URL Status:Offline
Host: 31.41.244.9
Date added:2024-09-09 03:21:08 UTC
Last online:2024-09-09 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: SunshineRay
Abuse complaint sent (?): Yes (2024-09-09 03:22:14 UTC to dl{at}redbytes[dot]ru)
Takedown time:10 hours, 21 minutes Good (down since 2024-09-09 13:44:04 UTC)
Tags:exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-09n/aexe d2933695af37c10388ff102f6193b2749545ece3b2e13dbc8c3c715396658423Virustotal results 36.49%Stealc
2024-09-09n/aexe 74043f1b65beb765b165993d916ee738bcaa0dab0e4e14bd8c9766519f753864Virustotal results 35.62%Stealc
2024-09-09n/aexe f1b88b7344a6563cd8bbc90b47df4edca9199672ebe8e78a2454232f2571ff2cVirustotal results 40.85%Stealc
2024-09-09n/aexe 66bf906782d56de0c137d3d9888f4e6271c6d75e6f2453b65879e5320cda09dcVirustotal results 41.67%Stealc