URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/prog/66d17d49c93d8_main.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3135407
URL: http://147.45.44.104/prog/66d17d49c93d8_main.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-30 08:08:14 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-30 13:40:28 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:1 month, 23 days, 2 hours, 23 minutes Bad (down since 2024-10-22 16:03:52 UTC)
Tags:dropped-by-PrivateLoader exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-20n/aexe 21892beb068b24aea47c1c958b6b12a74bd677b62bbeaebbd79b4fa556b1281bn/a 
2024-09-21n/aexe 21e10445f10920c11a5d2d894e77513fef8de3b040968198878850bd51e7d5ben/a 
2024-09-20n/aexe a7457db934f49952900772b7a3c137d0f4ef49d9729697bc654783bc61833cfcn/a 
2024-09-15n/aexe d43c9754fe10cb1f677f1ef7f9b018a186bd7de6c2e376e83734eaad3af8b53an/a 
2024-09-15n/aexe 7acf2671d13d618d6e7c471797890ff7ef9df81a0eeef31c3e211b4f0ce157ban/a 
2024-08-30n/aexe 82475d4397b6d833a0b170945b7fb607eb82e3609dc35dc51f04884be3a91155n/aLummaStealer