URLhaus Database

You are currently viewing the URLhaus database entry for https://petalsforchange.shop/current.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2797462
URL: https://petalsforchange.shop/current.exe
URL Status:Offline
Host: petalsforchange.shop
Date added:2024-03-31 19:08:07 UTC
Last online:2024-04-01 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-31 19:09:07 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:23 hours, 37 minutes Good (down since 2024-04-01 18:46:08 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-01n/aexe 9db2419625a793f23a3f1ca7946d560e37f3a16034b34eae442923a8f26583e1Virustotal results 51.39% LummaStealer
2024-04-01n/aexe 9735475f1dbaf1bee6dd9d1468b8e50d961efa34e9dada582ef804fa97432689Virustotal results 43.06% 
2024-04-01n/aexe 659290deab2df77ec4f6000797c647adeeb01e9fb9f1f7131f44b0235d62f0e2Virustotal results 42.42% LummaStealer
2024-04-01n/aexe aa63cc8550cb39473bed0fa22155d9bc5ce780dba9dd81449c75770799b22423Virustotal results 41.67% LummaStealer
2024-04-01n/aexe c0b4860057005ee1549b38ec8c27f1ac5c7888d4deafdacf9a7698c3edf378f7Virustotal results 40.28%LummaStealer
2024-04-01n/aexe 92bb1f19f3a6337be028edfb89c898d49927cbb732f94796251c70d29e8ba9e1Virustotal results 40.85%LummaStealer
2024-03-31n/aexe e1330b5e8d14691a985bf45fdc726ce7277ee98128791244290e9b5f79200818n/a LummaStealer
2024-03-31n/aexe 31b6a608393ad6cadd7eadf286795aef37260c9b99e837f1d7a1aa4e9a7f901bVirustotal results 40.85%LummaStealer
2024-03-31n/aexe daada19cab8e9cf064bfe1b219398dfa5ed5fe45832bfef1d5f284be93b4347dn/aLummaStealer