URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.16/inc/Firefox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3184299
URL: http://185.215.113.16/inc/Firefox.exe
URL Status:Offline
Host: 185.215.113.16
Date added:2024-09-21 09:19:16 UTC
Last online:2025-04-28 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-09-21 09:20:11 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:7 months, 9 days, 1 hours, 13 minutes Bad (down since 2025-04-28 10:33:28 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-03Firefox.exeexe ed9e4932c8a010bec2c803733932925e13c6803f291038a81fcd9c03025ffa57n/a
2025-03-14n/aexe 70885775cf3dc518a9b0001469604ecc9c748e3c6ec02915dd814c6eab9e0991n/a 
2025-01-26n/aexe 12697f3b85d29bc362aa7e9151b60f28339454e2ec1db0a8eee807feb7ca7e49n/a 
2025-01-22n/aexe 8b7916f5e35e136e6129cd5abb987f3d0bb97b76ed158ed1448227d61114bfdan/a 
2025-01-05n/aexe 7c1af1a44b23c72ebb8ce6573cb06e940a4774c504b6cc79dc727bd9ff59b70an/a 
2024-12-12n/aexe 9e17052913a7900daa7bf5fbd934043f7d9a489d545ac22f9c307ebc6366b14dn/a
2024-09-21n/aexe 9edbe8d6aee72e51c4d49d259faf757c71470e2036cb72d151d19512fbb0ddceVirustotal results 5.48%LummaStealer