URLhaus Database

You are currently viewing the URLhaus database entry for http://public-ftp.com/img/logo3.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2819467
URL: http://public-ftp.com/img/logo3.jpg
URL Status:Offline
Host: public-ftp.com
Date added:2024-04-20 11:01:09 UTC
Last online:2024-05-03 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-05-03 08:56:07 UTC to abuse{at}cishost[dot]ru)
Takedown time:12 days, 23 hours, 14 minutes Bad (down since 2024-05-03 10:16:53 UTC)
Tags:dropped-by-SmokeLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-02n/aexe ab1686a078433d515b501f5423b3046d6d1f70b2c9be21d2d3bf71b5d8465107Virustotal results 25.00%LummaStealer
2024-04-29n/aexe a65b290aa9ebfb82746cf75440c19956169f48d7dcbebafde6996c9b46039539n/aLummaStealer
2024-04-29n/aexe b6426c4324151df914b807fe68d0e4f5a15aea3a3082fcb7e4595a4b113f7657n/a LummaStealer
2024-04-27n/aexe 878966291372a9633242af15570a8bbe31699b5e0b650e806af4742da1f6b35dVirustotal results 3.51%LummaStealer
2024-04-26n/aexe 9e86e4796a51e2cae9487ec086aa2159b65a037808e70a0e7dbaf5a946a8801eVirustotal results 75.71% LummaStealer
2024-04-20n/aexe d040b1cad2d958a927b1a5552e455a2de58c2379b65050a853f383df9836f5b5n/aLummaStealer