URLhaus Database

You are currently viewing the URLhaus database entry for http://45.77.8.14/ssystem32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2496567
URL: http://45.77.8.14/ssystem32.exe
URL Status:Offline
Host: 45.77.8.14
Date added:2023-01-04 12:16:12 UTC
Last online:2023-01-04 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-04 12:17:05 UTC to abuse{at}choopa[dot]com)
Takedown time:11 hours, 8 minutes Good (down since 2023-01-04 23:25:42 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-04n/aexe c837a63ce5b9c5828fbf262e570947fbdc78ef081411f1cd0f22bd534ef55788n/aLummaStealer
2023-01-04n/aexe 16d5a7a60e4e29789e6596f5407415e47d292a32b5ec6a24eb28caf1295bd624Virustotal results 52.11% LummaStealer
2023-01-04n/aexe 022e9845dd95e4a747e72c7cca46deafc5c73a3312aca979b46445dadfb3f3edn/a LummaStealer
2023-01-04n/aexe ca06f761d4fb6312c45c097b5c1e6b038e81f2a18b93e65a05f7f6d42b100ab9n/a LummaStealer
2023-01-04n/aexe 81f6ada77be7ba105eeebcc42eecd623fdb666a56bbc18774332dfa435c26d16n/a LummaStealer
2023-01-04n/aexe 2253ed374a2bfb691c369e2ea71fa7d7715833501d8c50d53fc1ae75814cdb65n/a LummaStealer
2023-01-04n/aexe 982c702ecac5a029dedfe7d564913db598caf3e090d492b71478f48299088980n/a LummaStealer
2023-01-04n/aexe 845f812e3c912c1f686b9a499c1200bb9e5880d75c197ad5e191b75e057ff760n/a LummaStealer
2023-01-04n/aexe f68c63296d2783164728b1e94282b088c1261feb3a7e20b5293415d20523c75fn/a LummaStealer