URLhaus Database

You are currently viewing the URLhaus database entry for http://81.161.229.219/files/deluxe_crypted.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2717841
URL: http://81.161.229.219/files/deluxe_crypted.exe
URL Status:Offline
Host: 81.161.229.219
Date added:2023-10-07 06:58:05 UTC
Last online:2023-10-12 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-07 06:59:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:5 days, 15 hours, 25 minutes Bad (down since 2023-10-12 22:24:34 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-10n/aexe 5f18dec13e0158ced752a64a756248acef0524202a89fc94c97c923ab77039ddn/aLummaStealer
2023-10-07n/aexe 09bcfef16ebdb6eb335b71ec950e173c7488c0b071e7ad217ef66acf1e9bc5a9Virustotal results 34.72%LummaStealer
2023-10-07n/aexe c6f86c6f03bb9a5d62a0989fb6d3bc1f69b8bd023e2346fe4425ddddaa77e418Virustotal results 50.70%LummaStealer