URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/yuop/66b274e0e1b95_shapr3D.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3094146
URL: http://147.45.44.104/yuop/66b274e0e1b95_shapr3D.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-07 06:47:16 UTC
Last online:2024-10-22 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-08-07 06:48:09 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:2 months, 16 days, 11 hours, 24 minutes Bad (down since 2024-10-22 18:12:31 UTC)
Tags:dropped-by-PrivateLoader exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-16n/aexe 53a065fd224d3961f5d997a79b1ffb2a1fa3a2e7f98f9f370060f56f667de9d1n/a 
2024-09-23n/aexe 627f1c7e8d0ec7b842ee88aed084517d58d096b3621dd4437b3e1014c8b5b56fn/aLummaStealer
2024-09-18n/aexe 85e4171699c8424ba6e228f5d8a6b697f16b524e136201734a906f4c2afa6423n/a 
2024-08-27n/aexe bbc60dd00b271b95fa9e430df462dafa72c0a0f17f13cd6fa04bc8a393191145n/a 
2024-08-15n/aexe 4e824de7284e2c406063eccf3a72ca22a2d4aa7f6bd7b6b4cd1d85b1b79ea258n/a 
2024-08-07n/aexe fc678f0540da23c49928f774b88856d297ae5732f48e154279a78da2ff4af566Virustotal results 21.43%LummaStealer