URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.64/files/UNIQ.file which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2819462
URL: http://5.42.65.64/files/UNIQ.file
URL Status:Offline
Host: 5.42.65.64
Date added:2024-04-20 10:53:08 UTC
Last online:2024-06-27 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: Xev
Abuse complaint sent (?): Yes (2024-04-20 10:54:07 UTC to abuse{at}lethost[dot]co)
Takedown time:2 months, 8 days, 4 hours, 39 minutes Bad (down since 2024-06-27 15:33:21 UTC)
Tags:LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-14n/aexe 9d5d203c3b42d97ea56a408189df2d6f04c0f31c5fb3057178312252b3ea8221n/a Stealc
2024-05-06n/aexe a0da078a12df4c29c6036c0837bb55ae7761ff81aa80ad9e56cb153163b56566n/a Stealc
2024-05-03n/aexe 4a36ed71de45df239189409f8b15fb71d394064f60fdf99c135f4b930e20f481n/a Stealc
2024-05-02n/aexe e4ec01a727f591435836ae8fc2efbc0c10347433ca0d26bcb29b472f7a05abe9n/a Stealc
2024-04-23n/aexe d55e86610dcad29c3d2857d9dae91aa51228b1fa001ea2d7bda88b9a2b5570a9Virustotal results 40.85% 
2024-04-20n/aexe 28794b11097d9740a1bfce3e06458bccdccc167ceb75a140b4d031d052528d10Virustotal results 32.39%LummaStealer