URLhaus Database

You are currently viewing the URLhaus database entry for http://public-ftp.com/img/logo.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2817161
URL: http://public-ftp.com/img/logo.jpg
URL Status:Offline
Host: public-ftp.com
Date added:2024-04-18 16:01:20 UTC
Last online:2024-05-03 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-05-03 08:56:07 UTC to abuse{at}cishost[dot]ru)
Takedown time:14 days, 17 hours, 34 minutes Bad (down since 2024-05-03 09:36:29 UTC)
Tags:cutwail link dropped-by-SmokeLoader LummaStealer PureLogStealer RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-30n/aexe 97a8cbf52c015225390868a7d95e7a54dbbf7c29a9805783052458b72d92f8ddn/a Cutwail
2024-04-29n/aexe c92824e4a46135f56d4162ceba5765adf00264cb4305327509371259dfdb7e35n/a LummaStealer
2024-04-29n/aexe 878966291372a9633242af15570a8bbe31699b5e0b650e806af4742da1f6b35dVirustotal results 23.94%LummaStealer
2024-04-28n/aexe 93f357d221fc7f72bec7195e11c8a00b9e128448850a88ca66c8cc95fa47272fn/aRedLineStealer
2024-04-27n/aexe 8ea33dfd0e80f75db31401ac0a7402ec254c1f6be6445b3cc87433973b6f3fc2n/aPureLogStealer
2024-04-26n/aexe d5038b0adfdfc36c23dbaafd982bb50bb0e9fc10838e731e10d182d91b28d970n/aRedLineStealer
2024-04-18n/aexe 9e86e4796a51e2cae9487ec086aa2159b65a037808e70a0e7dbaf5a946a8801eVirustotal results 61.97% LummaStealer