URLhaus Database

You are currently viewing the URLhaus database entry for http://149.51.230.198:5566/releaseform which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3079506
URL: http://149.51.230.198:5566/releaseform
URL Status:Offline
Host: 149.51.230.198
Date added:2024-07-30 15:15:06 UTC
Last online:2024-10-15 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-07-30 15:16:08 UTC to abuse{at}northerncablefiber[dot]com)
Takedown time:2 months, 17 days, 0 hours, 31 minutes Bad (down since 2024-10-15 15:47:27 UTC)
Tags:extracted hta IDATDropper lnk-commandline LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-09releaseformexe 5f518cd2bbd4f56706e9347d300fe51cb21c11b63f54b2c9310267b077fd304dn/a LummaStealer
2024-08-07releaseformexe 2b223ea8a2f6ea7d60c38c81b6d2e2bcd4b70a73dcd74bc0136689bc4a69cf8bn/a LummaStealer
2024-08-01releaseformexe 6c2931402c355a24deb9edab5a1ad5544abac720613f78a1493e9a624b5aea0fn/a LummaStealer
2024-07-31releaseformexe 8dc6a5712056740bd4f9a390ee3bb1c3f80618f907d1f0f43cebced7dd02b514n/aLummaStealer
2024-07-31releaseformexe 324fe42a69f298ce756c7a3179e34ef0b051a660b3d9b1ca83b6e05007d823c3n/aLummaStealer
2024-07-30releaseformexe 1f194878aa557011e83bd5c1c6fab11956322688a35ef0fbd0bb876fa667c5f5Virustotal results 22.67%LummaStealer