URLhaus Database

You are currently viewing the URLhaus database entry for http://193.233.20.36/lend/Gmeyad.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2590907
URL: http://193.233.20.36/lend/Gmeyad.exe
URL Status:Offline
Host: 193.233.20.36
Date added:2023-03-30 05:51:12 UTC
Last online:2023-04-18 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-30 05:52:05 UTC to shinomiya[dot]hosting{at}gmail[dot]com)
Takedown time:18 days, 23 hours, 30 minutes Bad (down since 2023-04-18 05:22:55 UTC)
Tags:exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-05n/aexe a1ad4f1cbaef3f0853c343b3732c60ac2c60bb00ee97c2ea11ed735956333b7bn/a
2023-04-04n/aexe 78f5b77edbc8e63bdb279aa6fb32365045f904725e2212ff846afde2eb40d5ben/a
2023-04-04n/aexe 5ebf2c9ed8804732ce0ffba0be8912ac78321f763ddd9cee221f0df0ba61779dn/a
2023-03-30n/aexe 7fb411ee3e34e4b79b372b7d2321bf69b46de30c3286edccb7621562caefb60bVirustotal results 61.22%LummaStealer