URLhaus Database

You are currently viewing the URLhaus database entry for http://185.235.137.54/file/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2842945
URL: http://185.235.137.54/file/update.exe
URL Status:Offline
Host: 185.235.137.54
Date added:2024-05-08 10:02:05 UTC
Last online:2024-05-09 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-05-08 10:03:08 UTC to abuse{at}hostzealot[dot]com)
Takedown time:1 day, 3 hours, 6 minutes Poor (down since 2024-05-09 13:09:41 UTC)
Tags:dropped-by-SmokeLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-09n/aexe aeed9fee5629c55cf8540485dc9ba151d33ac6869623f9e6327f7f746f9eb8f7Virustotal results 36.99% LummaStealer
2024-05-09n/aexe ac455193c6badd59e8fc876cf2c81d3e9100d13361fa148ff2cf81b07c6cc6b5Virustotal results 37.50%LummaStealer
2024-05-09n/aexe 2e3818a168bff294f7e7e1f3ac84ed8fb4b643f3d18db9526c36d392392728e3Virustotal results 36.99% 
2024-05-09n/aexe b35db130bb99fd4ad635312c17c1aa34b4de1d6c4faef48ac02ca9913ff23bddVirustotal results 44.44%LummaStealer
2024-05-08n/aexe 4a4d61eb977b43d044573d215a6a112562960969288b170e8c7ab22c635c234cVirustotal results 38.89% LummaStealer
2024-05-08n/aexe 4bd5755f9f0f468a1f8996b8bc3b916ea5e5b83a802240617b39cd392021c669Virustotal results 39.73% LummaStealer
2024-05-08n/aexe a3a4d0f984693a13a21bd920bb133dc16b5dab2a761c93275d716fcbbc5b35b7Virustotal results 41.67% LummaStealer
2024-05-08n/aexe 058ff3bb0edcc9995c2c8fd1ab6639815f2addb39073c4a635ea4eb136ffc372Virustotal results 41.10% LummaStealer
2024-05-08n/aexe 1f5be9580acd827ce8d2fdf01e33852009d3a3aed4d4587c062dec03dc12222cn/aLummaStealer