URLhaus Database

You are currently viewing the URLhaus database entry for https://changingpetals.shop/current.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2794258
URL: https://changingpetals.shop/current.exe
URL Status:Offline
Host: changingpetals.shop
Date added:2024-03-27 22:59:11 UTC
Last online:2024-03-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-27 23:00:11 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:1 day, 14 hours, 3 minutes Poor (down since 2024-03-29 13:03:45 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-29n/aexe 4186cc5d433442d26c0d651ef3470235dc7529a709af3ce9772231ee0b47fc1eVirustotal results 41.67% LummaStealer
2024-03-29n/aexe d24e8165b677587172cd695c6df3836c8bde35a26188bf04d55ab9c0294c97ffVirustotal results 38.89% LummaStealer
2024-03-29n/aexe 2c3c32b6df96221ee36a9d893d7750fd3d05a42d13b1f52400101038e5564fe7Virustotal results 38.89% LummaStealer
2024-03-29n/aexe 3f843f9cf9346c56f29bceee03b9512d84a92bd94b7b6f4ee668bc4a6e3f8047Virustotal results 38.03%LummaStealer
2024-03-29n/aexe fe2ad4001c817a77de2e7d4ca694833fef66c99beee799333fc84e74da4cad5eVirustotal results 38.89%LummaStealer
2024-03-29n/aexe 0701e32e26de227576fdd678f76ee479e40b7bbee2f2ec0f9cba54c2320d57f3n/a LummaStealer
2024-03-29n/aexe 85745378225bd821638a044b220923457b24ba2cf79da32e7ecc8c53e012cdf7Virustotal results 36.62% LummaStealer
2024-03-29n/aexe 57932d45096369bff823747c74a1081b4ab6c862635e7562193bcb4062f8d243Virustotal results 37.50% LummaStealer
2024-03-29n/aexe ef3578dc75545fd41e365a2919979429d605b381c53812e867adddfe36ac7849Virustotal results 38.89% LummaStealer
2024-03-28n/aexe 4a5ff59b90eb5766041a14ba8b6dd14b34d814f4f2a41d03bd6b6d70cd30cf24n/a LummaStealer
2024-03-28n/aexe d5b569e891e07a132311bfacbff3e81a5421ff9d0a8e8f1380cd6e221a621dc6Virustotal results 38.57% LummaStealer
2024-03-28n/aexe c0d3059483686a630ad570496898d637bd475d2ccff3b9483a1f8d1a4feec4c8Virustotal results 40.28% LummaStealer
2024-03-28n/aexe 261e4c8a96982b9af5ac4e55fbe9dbb4559f29803ea11832bc07622848abec7cVirustotal results 38.89% LummaStealer
2024-03-28n/aexe 0c3266f0412afb4e5cce38669ede9fa186da8210cca39eb1d47b4e809149af5eVirustotal results 40.28% LummaStealer
2024-03-28n/aexe 390b09170977924f625816495c9deeaa29d77b2d58bcc2fff7f2889e8cde224dVirustotal results 39.44% LummaStealer
2024-03-28n/aexe 6848f27dd5784dd54d5e3dca2210e884315192a6e01ecf7f79be3b625b0654adVirustotal results 40.28% LummaStealer
2024-03-28n/aexe f6fdd1efcd17813514cdabda3cbfa77b35f74bb8de0992dbe72fc9fd53ec5c81Virustotal results 36.62%LummaStealer
2024-03-28n/aexe b484b5356d00aef00d35c1339aa0c8937f2725cdccc06156d1941ca6bf63efb5Virustotal results 45.07%LummaStealer
2024-03-28n/aexe 64f518f278d1f80c480e8e96414606be3383b07ca7571b5eae64df0ee88d4074Virustotal results 43.66%LummaStealer
2024-03-28n/aexe 2b1039f5409827b3452a6d2c98879b7b5be243f8943bc54237fd10d97af37399Virustotal results 40.28% LummaStealer
2024-03-28n/aexe 185fe49f3d7903976d56a7e353c3113699995517aaad57f8d44273230520029fVirustotal results 38.89% LummaStealer
2024-03-27n/aexe db15fa70e559db760ca11ab2a86159d7899c226b9166f71c84c91e178d511df8n/aLummaStealer