URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.9/guna/sera.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3168613
URL: http://31.41.244.9/guna/sera.exe
URL Status:Offline
Host: 31.41.244.9
Date added:2024-09-12 10:41:05 UTC
Last online:2024-09-30 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-12 10:42:08 UTC to dl{at}redbytes[dot]ru)
Takedown time:17 days, 14 hours, 19 minutes Bad (down since 2024-09-30 01:01:26 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-13n/aexe 29ccb9b73cef0dec4afe5a18560b5b65e0731c7e1030d753267c262cd9c2f3a1Virustotal results 51.35%MarsStealer
2024-09-13n/aexe 9b8e5b5f2e62640327fdd1616c62a29ec27eaddad731d66ed331b3a1135fd6cbVirustotal results 48.65%Stealc
2024-09-12n/aexe 45bbfe6526c7aa0ac16355e301a467c2533bb1b2455dea1405deb80be734f990Virustotal results 51.35%Stealc
2024-09-12n/aexe 19c4afdea818ee9bf72caf10b4670bf70ab4c71ea54a3d42b10b7231d58fa5d7Virustotal results 52.05%MarsStealer
2024-09-12n/aexe bad250bc479f9d326fc76a6f914f56ca5a1944fb2e5c75710ab9add80e5ac9e4Virustotal results 50.00%MarsStealer
2024-09-12n/aexe a23e1bcc61ca1ec01443b28086f0920f5189d26c58e6692222af6ce94a06263dVirustotal results 41.82%MarsStealer
2024-09-12n/aexe 299c378868c76048c26d0e279655c08305f0ce42e5582fe5005aae776d525a1bn/aMarsStealer