URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.103/doun/game.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3182925
URL: http://185.215.113.103/doun/game.exe
URL Status:Offline
Host: 185.215.113.103
Date added:2024-09-20 14:12:09 UTC
Last online:2024-09-21 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-20 14:13:07 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:21 hours, 48 minutes Good (down since 2024-09-21 12:01:30 UTC)
Tags:dropped-by-PrivateLoader MarsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-21n/aexe d3155985f0c2ba38347e66b3b68b84e695493cd5bb0b8420a557056184fa684fVirustotal results 52.05%MarsStealer
2024-09-21n/aexe 65ea0de5671dc49d48d06574d99a42bf0d4887e32e4673e25c66169ae28583b2Virustotal results 55.56%MarsStealer
2024-09-21n/aexe deb1bd627ce6aa3176c16ca5270eca5dda7a7e9ba7f56d510a1dceaba620e05dVirustotal results 50.68%MarsStealer
2024-09-21n/aexe f310f508de6011bb8066c1dd58e22e2d3b9e15b9d2f830d53095b8c97e0d56e4Virustotal results 50.00%MarsStealer
2024-09-20n/aexe 2da1e8bf03c5a80048834e56af5cf384e87986b5b2e59d6acb436d9df20d0203n/aMarsStealer
2024-09-20n/aexe 0694dc94512d5b3f7499ad78ae042bdd48352f7d2c9abaf04834644ab6859d5aVirustotal results 46.58%MarsStealer
2024-09-20n/aexe 2d728eb2d7d582a3560d8c8db72fb3ebfc14ff263dad1dd353ff72081a9c2329Virustotal results 43.84%MarsStealer
2024-09-20n/aexe d448fe9d22d4e34cfba0a5f0bcaeeeb2f2daf6f4bd5ed8996ab427ea87bed173Virustotal results 43.84%MarsStealer
2024-09-20n/aexe 47145906198e907f3fbe78ef580175b1c399d04673d3f1c759f0ba4b18355a2cVirustotal results 43.84% MarsStealer
2024-09-20n/aexe f191cc28ee681ea36c73780f422739493d6e8db494c07534a9ea2a688b02595an/aMarsStealer