URLhaus Database

You are currently viewing the URLhaus database entry for http://82.147.85.52/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3077633
URL: http://82.147.85.52/build.exe
URL Status:Offline
Host: 82.147.85.52
Date added:2024-07-29 15:06:06 UTC
Last online:2024-09-03 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-29 15:07:08 UTC to admin{at}vpsdedic[dot]ru)
Takedown time:1 month, 5 days, 9 hours, 27 minutes Bad (down since 2024-09-03 00:35:03 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-12n/aexe ed1b8cb130c9f5dfb7889a60c6cde36d86635c39cf59c7d9e57d5d1ec17784ffVirustotal results 50.67%LummaStealer
2024-08-05n/aexe c3e3e6dffe3c25265a1c84a0dad2d0821d4ea9b1556a82f2822c2038ad2369b7n/aLummaStealer
2024-08-01n/aexe d74824afe32a8968ea5dcb2c4f218acad08f345b4df52e9a5e03de0ad5c89966n/a LummaStealer
2024-07-29n/aexe 35e5f8f573216bf3c4d308c8556ac17043986cfd17a9f25824ca54f7a2483892n/aLummaStealer