URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/prog/66b5ac1092454_otraba.exe#otr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3097299
URL: http://147.45.44.104/prog/66b5ac1092454_otraba.exe#otr
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-09 08:48:07 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-09 08:49:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:2 months, 14 days, 8 hours, 37 minutes Bad (down since 2024-10-22 17:26:30 UTC)
Tags:dropped-by-PrivateLoader exe LummaStealer njRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-19n/aexe 05554c9a194b79ee511eda20a800b9a9a99510a8ffd7aac0105b34a6c91142d3n/a njrat
2024-08-20n/aexe 2df554d9da027400ee84e8a518f9b226dd6a87c932da77ffb60b8ce64600c3f9n/a 
2024-08-09n/aexe 022845dbd0b028f17d257923279a9adcde5c7e4024f219059e0682c3825b7eaeVirustotal results 16.00%LummaStealer