URLhaus Database

You are currently viewing the URLhaus database entry for https://changingpetals.com/current.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2790629
URL: https://changingpetals.com/current.exe
URL Status:Offline
Host: changingpetals.com
Date added:2024-03-23 11:33:11 UTC
Last online:2024-03-25 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-25 00:33:08 UTC to abuse{at}cloudbackbone[dot]net)
Takedown time:1 day, 19 hours, 44 minutes Poor (down since 2024-03-25 07:18:46 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-25n/aexe 46a8847d9b5339fcadfbaf158c5775c5ab2965f014afa009671573b4d9d1ce2cVirustotal results 46.48%LummaStealer
2024-03-24n/aexe 58a2f2d69d039829f5e5ea043742552df8adc0ea60441d0248dd270c07165b7eVirustotal results 41.67% 
2024-03-24n/aexe 2b315b5bae4558495a7097ddef58cb48927bc183ccbec6ccdaa71c6353a9d5a4Virustotal results 39.39% LummaStealer
2024-03-24n/aexe ef0f2ca71bcb2b40a2565f6d39b93eee204e29e39ac54a6bfe04d2cd157e4e45Virustotal results 38.89%LummaStealer
2024-03-24n/aexe 5fad09bde8551c6f4df812e50bd9917a71463ca93359bf73ecfbe05967c3203eVirustotal results 38.57%LummaStealer
2024-03-23n/aexe 52f658d7269f22712bc11108921327d1ab2d089b22805390eab97d66a1bf429eVirustotal results 40.28% LummaStealer
2024-03-23n/aexe a4371736bfd32aa3e398af167348438cfbc72b484f12fc03d4cded8f9490b2c9n/a LummaStealer
2024-03-23n/aexe 58bbd8b750c588cb1fbc1fa7d78e893456baa38b936d689ab902443286d0322fVirustotal results 38.89% LummaStealer
2024-03-23n/aexe 2b67ea5b85b5f1ea8426d4c0e1380a791c8519222de42da9f86bbf1ff724886dn/a LummaStealer
2024-03-23n/aexe a50315e8758118f4fd40b50c05242c1293eee104336da3cf2bfca2d6dc64ec02Virustotal results 40.28% LummaStealer
2024-03-23n/aexe e1d3a9a0ce88a02aae8e67f0e37f0682677bd1b791767460566f4f645fc443c3Virustotal results 39.06%LummaStealer
2024-03-23n/aexe 944acac373a28c754566ded96145a946e3a9247eb12a9ddc5c02c45a2523fd4bVirustotal results 40.00%LummaStealer