URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/prog/66bddfcb52736_vidar.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3114130
URL: http://147.45.44.104/prog/66bddfcb52736_vidar.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-18 11:40:07 UTC
Last online:2024-08-21 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-08-18 11:41:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:3 days, 6 hours, 8 minutes Bad (down since 2024-08-21 17:50:06 UTC)
Tags:exe LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-21n/aexe f41e569fd72766fdd1276d9b52d3e4b1aa7ae8f4731fdc199774a4bff31628e5Virustotal results 32.43% 
2024-08-21n/aexe 4f4bdab7395c314e035dc7573c0654aec30e45b1402de63fac8e96c0c754875fVirustotal results 29.33% Vidar
2024-08-20n/aexe b8af4212019603dad1b32988c489f871672c5090f8d1013818a4b91363ab038aVirustotal results 34.25% Vidar
2024-08-19n/aexe 46d76e5ef444f4a21be37e7f86457c8d65d5855a1d511a4c86ef91bb3224e57bVirustotal results 25.33% Vidar
2024-08-19n/aexe bf2a40a57140c97f9ea2f587fd21f0c1df4ba22222e93dba9bc3fdb705937da5Virustotal results 21.33%LummaStealer
2024-08-18n/aexe 229c3895912d2d9ed72131b20380ccca556f9e158ceb20197640bf0aca5ce7c8Virustotal results 36.00% Vidar
2024-08-18n/aexe 2a022db22575506eacab526bd1976871f842b9c306a9a3c8b1fd69421b0b891eVirustotal results 26.67%Vidar
2024-08-18n/aexe 18c2fdea6936d96d1a707202e56f02857bae02b17cea62515a11f139cab46eb7Virustotal results 51.35%Vidar