URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.11/tura/niko.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3205947
URL: http://31.41.244.11/tura/niko.exe
URL Status:Offline
Host: 31.41.244.11
Date added:2024-10-03 01:25:09 UTC
Last online:2024-10-06 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-03 01:26:09 UTC to dl{at}redbytes[dot]ru)
Takedown time:3 days, 13 hours, 7 minutes Bad (down since 2024-10-06 14:33:26 UTC)
Tags:Amadey dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-06n/aexe edc4cecc706b346cb826c4cf84f94b7d1cd918bd084841736a279bd434ba2b17n/a Amadey
2024-10-06n/aexe 16d7f4957e4fbe07e8fe1cd57e83496ebf572ec0d3bae2931ceb314b515d18f1Virustotal results 55.56% Amadey
2024-10-06n/aexe 92b360b9f25aa2f599011d1d83877fef994eb17113fd653e63a02cf2e067059bn/a Amadey
2024-10-06n/aexe bdeea4df26f96beb54d885f8e0f5171abb5d6a3180f123e715ba1c829ff3b92an/a Amadey
2024-10-06n/aexe 2d67fa613399a5575cf7d08f0c19fe8b76713e15f6487a0e172e34ceb78cede2n/a Amadey
2024-10-06n/aexe 4746dcb12c46dc12cdfff5edf16d6829bd544bffb1f7d60f7424783c73fc2513n/a Amadey
2024-10-06n/aexe f494451254ca17346f3d393d42c147f79e977a0d4b4f7625c3744c58cbbf268an/a Amadey
2024-10-05n/aexe 27b09bf2dd3b6545dd7cbd0817c24c60bb9111aebc4e6af76691f91556c213ddVirustotal results 54.17% Amadey
2024-10-05n/aexe 097daacfea7a631baaf75ae51976b85dc74ed3548bb9be57e6976cb4b65f9de6n/a Amadey
2024-10-05n/aexe 6ca5880703677761658116018020b34930074065ee899f1482b707c42ab35666n/a LummaStealer
2024-10-05n/aexe 7338e572d2ec7f42b77315c3c159c9fa9b2ee71999af15a12bed97d85627028dn/a Amadey
2024-10-05n/aexe 621864357892326ea60042a4dc66c7c8390b35b2151ab2c642d5733f160db43an/a Amadey
2024-10-05n/aexe 29460f04d8b6813b77d32ba4220fc057eab21895cdb635fca254541506e0da9dn/a Amadey
2024-10-05n/aexe bcab931891fdd64fad1c6c2db4a71cd43085494cb7b02274894d8529be05a66bn/a Amadey
2024-10-05n/aexe c60f03c1aa7dfedc9655aa06796abd3f6621dfdd2975db1e23f273574392ea83n/a Amadey
2024-10-05n/aexe 0c0db44d26ba6a1781dbd7b81ce35a751f54cb64fb8691806ffb1fb6b7487674n/a Amadey
2024-10-05n/aexe b601f5de57fdb969b5891e6b3e1fb39bc3b8b19c40e5608d387b61c06d937c88n/a Amadey
2024-10-05n/aexe 564f751cd22e012b53fc97938a7ada2f5ef769e56713b3eca916cc7ddb05fd57n/a Amadey
2024-10-04n/aexe d2cbab426619ea4437d8cf9c40a8ebdec8a33fb47f1ad444988d8b66686c9d3eVirustotal results 59.72% Amadey
2024-10-04n/aexe 29a4d509f4ce69d657695ee29a9099449fa82d86829a343fd078d9fe012eee37n/a Amadey
2024-10-04n/aexe 822b65f1fcdb9164bd340c35103411b811eae238b300c585bcd4721f330e4b82n/a Amadey
2024-10-04n/aexe f78a5d3716dcf0b473feec0ad2e0cc8b8bd98f94e06d902ac82bc0ddcceb8b61n/aAmadey
2024-10-04n/aexe 2c9bd8f07ae20ed82daa5cc56579b87a2e74a16ce12abc8fdd7118cde5689c4eVirustotal results 61.76% Amadey
2024-10-04n/aexe 30ce80cadf04ae5d57ac660f6fd1d17913502b5d4a71ac7a78f754bb695df254n/a 
2024-10-04n/aexe 6f7af9607a4736c807468d4b1354124f2029b1478e0b08af90bbe94bccc7e826n/a Amadey
2024-10-04n/aexe df708393485e8788787e6292ecef020928ecea7dcde2c5bca9e9868834d2b136n/a Amadey
2024-10-04n/aexe 41bdf59efc1b3f896d0ccd11b5f1326b1fd74371d42a0b748b354c50abe8ce00n/a Amadey
2024-10-04n/aexe f16a08f237ceab9ae7c5d281c97e5bf7602484e0886384804b8e3912c4ab7d94Virustotal results 49.30% Amadey
2024-10-03n/aexe a7a72700a6016d8667f88810de38b543711a784033db85dd43b26c4936917c2eVirustotal results 56.94% Amadey
2024-10-03n/aexe 2b9a77201b04ffe46e2927d91c390fa0d69153cfa95a4f87765c3c40100fd1e6n/a Amadey
2024-10-03n/aexe 62efbcb39b3a11652bec4357241dfbe099eb91ee56d6856a531ce7c29c2eb002Virustotal results 55.56% Amadey
2024-10-03n/aexe aac3f06ed5557c43201e378292028e7e4dea7802cce020cf7bfec26f8e57dee3Virustotal results 55.56% Amadey
2024-10-03n/aexe 45db73cdac73c20ac15510b593273d18a9359fd4bf448ae9a56d2f966e178ce2n/a Amadey
2024-10-03n/aexe 4c6c74a34118a3207b6720664620c304c535f627bf891b43cfe0b7f7f83b04b4n/a Amadey
2024-10-03n/aexe b24587f93e2c5d8ea3cebc2c265df906fcf979f9d8a77a0d9276514c14adb815Virustotal results 56.94% Amadey
2024-10-03n/aexe c0cfa9b5e4a52c7a788fe0855343e397530fd2a6c05d7b07799779a80b9128c0n/a Amadey
2024-10-03n/aexe 7812f506aaf981a74ca9c824835bc35e8a3ccebe5afd08eabab2da458576bc32n/a Amadey
2024-10-03n/aexe d197066ae68ab7f2c02cfb7aa6e0655e04748301047a71a5140a7ba64e04d89fVirustotal results 58.33% Amadey
2024-10-03n/aexe 1a6fc3b2bda9a9615ec0f20492bd75257b41581e9ccef8d2c04f26642d985632Virustotal results 59.72%Amadey