URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.64/files/EU.file which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2819458
URL: http://5.42.65.64/files/EU.file
URL Status:Offline
Host: 5.42.65.64
Date added:2024-04-20 10:53:07 UTC
Last online:2024-06-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Xev
Abuse complaint sent (?): Yes (2024-04-20 10:54:07 UTC to abuse{at}lethost[dot]co)
Takedown time:2 months, 8 days, 5 hours, 21 minutes Bad (down since 2024-06-27 16:16:03 UTC)
Tags:LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-14n/aexe 00ca90e01fedb9c290e30a733e1dd9a7642f57bbdde830c7a5be114f731e3382n/a LummaStealer
2024-05-13n/aexe 27a5a8361389a3b4c09a21e61a96bf14c3d48e3a79f842710d4aaa3a29f844cdn/a 
2024-05-08n/aexe 197aaacf854d87e4cf438f1cb0ffe00c04d2a7e7540b3dc4b47c574f367bf195n/a LummaStealer
2024-05-02n/aexe b81663c39190473eafc5e543b70729a2888f2ed2490dc4ae7d9ec92d97575085n/a Stealc
2024-05-02n/aexe 3434ad1abf70a8cd871bb38ba1565b00d37d8d0c800528ee5675f279371ee7e0n/a 
2024-05-01n/aexe b9f9a311bca1faa3b4207a154c809f2a8d11cfa14a1e037bb7370a0bec07bbben/a Stealc
2024-05-01n/aexe 76ce4536160498b72879a07b4d7f19f9d9d89c9cb78dcad8dbf1b1fa28138134n/a Stealc
2024-04-27n/aexe a98da152725af2e2fcb819a37d1e0893150c8e05bc17501db97f6bcc6af4ece0n/a 
2024-04-20n/aexe d55e86610dcad29c3d2857d9dae91aa51228b1fa001ea2d7bda88b9a2b5570a9Virustotal results 40.00%