URLhaus Database

You are currently viewing the URLhaus database entry for https://mussangroup.com/wp-content/images/pic4.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2923982
URL: https://mussangroup.com/wp-content/images/pic4.jpg
URL Status:Offline
Host: mussangroup.com
Date added:2024-07-04 11:55:21 UTC
Last online:2024-08-28 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2024-07-04 11:56:10 UTC to info{at}veridyen[dot]com)
Takedown time:1 month, 25 days, 0 hours, 42 minutes Bad (down since 2024-08-28 12:38:24 UTC)
Tags:dropped-by-SmokeLoader exe LummaStealer MeshAgent opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-28n/aexe ffc6c7ec46ef8cc1d6001f2f12fd439322925ba22b5639a01fe32d7f8ac58bd5n/a LummaStealer
2024-08-27n/aexe 4b16b9168f582448d16e99701ac2350175a369004fe52367bb0fdd4fbf423efbVirustotal results 32.00% 
2024-08-19n/aexe 3b4e957af06ccd4e6286552e543f216bd829abffa0e7a93eeaffb80a9c4a7a92n/a 
2024-08-19n/aexe 64c753b6290b57c01b8e9de93c48ab3546f0cdb3d43c5ddc683005606ba70183n/a RedLineStealer
2024-08-18n/aexe 12304b7c8fa917092a9b51195bc8fa9f8ab33e4fe7dd0a5c62d2e9014d05233fn/a MeshAgent
2024-08-10n/aexe 24b5de5dff6997d0dc7e1f400e61bcb4bd6806eadbaa2367d62cddf82a2dedfcVirustotal results 21.92%LummaStealer
2024-08-09n/aexe d4aafdf7261fb41ef48370eca3e4d70a9086528d7c3d14fc8c82fcb8b69710cbVirustotal results 29.33%LummaStealer
2024-08-07n/aexe 7b61dae8513cbd3bb0617a191e4c0306989a632632e7700db7a0d68d154fdc16n/a 
2024-08-07n/aexe b1ccda9f7ba76b222d9387f6ee8cbbd3222af3dc3723a247c6e80cb0a5626676Virustotal results 29.33% 
2024-08-06n/aexe 208cf6b8c728eb97c9347ee014dbc3dabfc13445531a2c6f27883fd38f3bd02eVirustotal results 14.86% 
2024-08-05n/aexe 68e0b6f27bbcdc97b12e97d597dd59e5ec7267bd7d11e39cc1c718acc5058564n/a 
2024-07-29n/aexe 9ef9790e533d1af2b1b365b1384ab3510857abdce434e9d8ee53728fb7ae0bfan/a LummaStealer
2024-07-22n/aexe 92abb324f8f4afee6d52409324c728d1e4577883c1f4f58282f1cee9105952cfVirustotal results 11.27% LummaStealer
2024-07-18n/aexe 0e2c8cea910a4b0602dd22645eee8b60a93f4e745310de262eaa4d439b0fd0b0Virustotal results 15.07% LummaStealer
2024-07-04n/aexe a173db1e8568fc4b00f326d52af0fea19c59639c486d9975589edfd8f1a11da1Virustotal results 20.55%LummaStealer