URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.100/guna/sera.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3170525
URL: http://185.215.113.100/guna/sera.exe
URL Status:Offline
Host: 185.215.113.100
Date added:2024-09-13 12:33:08 UTC
Last online:2024-09-15 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-13 12:34:11 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:1 day, 23 hours, 48 minutes Poor (down since 2024-09-15 12:22:56 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-15n/aexe 2ad58a19b6fa3da5164d9605013afc116c8acd825da19b4885f567e1839a3527n/aMarsStealer
2024-09-15n/aexe caf735b57caf7322a7db8a0ed079644e829d2a4a53419bf7880e7f4031af678cVirustotal results 50.00%Stealc
2024-09-15n/aexe c93d85b5ab85677964972deb920a4ab9999127556b55af7251bc9361660e8692Virustotal results 50.68%MarsStealer
2024-09-15n/aexe 0f2529c2f543d283cce5a41ca755a79b6660f9da773f4e49937a937319064248Virustotal results 52.05%MarsStealer
2024-09-14n/aexe 4b0a44c5c46b353abd46e4f68f73f51123d00aaf5450d0953a84484a5f25e63fVirustotal results 50.00%MarsStealer
2024-09-14n/aexe d1e4fc4076ec33d50bd9582e49a2b46b9e40b5d54fe71519ecfa73dab5c64e50Virustotal results 52.78%Stealc
2024-09-14n/aexe b6366970921b26d2710fd6b1faba2f8b41a2d0f5f8abf88696722ae827ab769fVirustotal results 54.17%MarsStealer
2024-09-14n/aexe 2cc4e2def2174f5efe56a9bf430b10fd9dcef4093d7d32c7bc826e6e194a046eVirustotal results 52.05%MarsStealer
2024-09-14n/aexe 2b23b21ed20b273bc32a8398c8d07254e003996025e610d1b422533fc6091687Virustotal results 52.05%MarsStealer
2024-09-14n/aexe 4f713a5c8c50737939c18aa6cf6d557e309abd14a461d0189c4413ece7d06e96Virustotal results 50.00%MarsStealer
2024-09-14n/aexe 0b5ec1e45683ed73f1825ac1ecb188a79fb76b6f99c39a3d05f40caeae8191e7Virustotal results 52.05%Stealc
2024-09-14n/aexe e2a1770da6d6838de2454af91092c33eb7f2c933617422826e2a15240f967266Virustotal results 50.68%MarsStealer
2024-09-14n/aexe 4315e182b415d4fa0165bb4d386e3b96d26504351e0df049d387867e68ceadc6Virustotal results 52.05%Stealc
2024-09-13n/aexe 6674f0a92e479a5a6c2f2bc496300070a1c706e0f013924256ebdd221010a68fVirustotal results 52.78%MarsStealer
2024-09-13n/aexe 152a7f2926e2f6182303dfca985b78290047dc9a8260ff711503d7a5e801f5eaVirustotal results 52.05% Stealc
2024-09-13n/aexe 9cd0a3de166d30132be56aed6c643583f4a78218e68ecb2be220560cdbd360d5Virustotal results 52.05% MarsStealer
2024-09-13n/aexe 19ea28b761e263b381b52bf0674aa36808e79d2e8a98617852a1635afeccdbc2n/aMarsStealer