URLhaus Database

You are currently viewing the URLhaus database entry for https://changetheworldwithflowers.shop/current.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2810731
URL: https://changetheworldwithflowers.shop/current.exe
URL Status:Offline
Host: changetheworldwithflowers.shop
Date added:2024-04-13 08:52:05 UTC
Last online:2024-04-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-04-13 08:53:05 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:22 hours, 13 minutes Good (down since 2024-04-14 07:06:24 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-14n/aexe a61f052691363695c4c90e9e93cd85fcee6f1b4ffa25e7e7f334ef9dcb99cd61Virustotal results 38.57% 
2024-04-14n/aexe 7a10985ae61a58aa3fc98544f9cddb8e2f78625a4a07a2a729ca70f84a6d5f8cVirustotal results 41.43% LummaStealer
2024-04-13n/aexe 46ded7d187787bf2c851d875dfa2a02dbc95356d01c30e7b9807890fd1ed80b7Virustotal results 42.03% 
2024-04-13n/aexe 7b40df38252a0aeb2050fe919565fe573d4766552a86570f9fdedcbfa9f8abcfVirustotal results 37.14% LummaStealer
2024-04-13n/aexe 7ba422eb82f15c98129173f207bcbbf2ab4abe355dec287a23a69fbdc921e385Virustotal results 37.14% 
2024-04-13n/aexe de6d97aaba9ebde761332cdaa5db33eb30f603e98493aa827d339adf6cb09f7dVirustotal results 38.57% LummaStealer
2024-04-13n/aexe 38c96258463ac376cfc366ef4c1eecaf7af2c0fe3107b0a2b0fd6ffd8e383ba0Virustotal results 35.71%LummaStealer