URLhaus Database

You are currently viewing the URLhaus database entry for https://merchentusindiajute.com/ss.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728700
URL: https://merchentusindiajute.com/ss.exe
URL Status:Offline
Host: merchentusindiajute.com
Date added:2023-11-07 04:37:08 UTC
Last online:2023-11-08 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-07 04:38:04 UTC to abuse{at}cloudtechiq[dot]com)
Takedown time:1 day, 10 hours, 22 minutes Poor (down since 2023-11-08 15:00:28 UTC)
Tags:32 exe LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-08n/aexe d49e3fe3bd14ee37eadcbd6df61cffad9d6963e88b92cf5269361071ed429385n/a LummaStealer
2023-11-08n/aexe 3c2dda9881c9528f3739355e1b7162f5706ba7bd00502f523a520d1f1485954cVirustotal results 30.99%Stealc
2023-11-07n/aexe 7d02e20a4a9672e842864c3abb108250296ac693e63151c8f2783a315b89ed19Virustotal results 25.00%LummaStealer
2023-11-07n/aexe 0762b2ba2bf925463ea8662e76030861754ab4d1c7aff8c1005d246921b35db1Virustotal results 23.61%LummaStealer
2023-11-07n/aexe 1bcd064a8d5d8cb8e607c7b6b8a2575a9c7de02439477b9b77be747768ec9da2Virustotal results 31.94%LummaStealer