URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/yuop/66f18a5501651_ww_a.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3187811
URL: http://147.45.44.104/yuop/66f18a5501651_ww_a.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-09-23 15:36:07 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-23 15:37:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:29 days, 0 hours, 29 minutes Bad (down since 2024-10-22 16:06:37 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-18n/aexe 1bf16b4db13e1dc100876638e1c11d3bb7ac78e7c73c059f88521177629950d8n/a 
2024-10-17n/aexe 1284252c127b46a4de1bf7461da97559fcee3d45750fcd6df824271bcaa33ea0n/a 
2024-10-10n/aexe 9c886f49f546179537028b0e8ed49d3fc674b05651c8dabb44c2d8859a60227an/a 
2024-10-09n/aexe ff9dc757f25c94b9deb8aaa62be643d803e1a1b18f2b3506d2cb306ebee91a17n/a 
2024-09-29n/aexe 8b76789ef9633073443bb2fa1f1bcb99f8c271a9bfa2a24a3134a2003655d330n/a 
2024-09-28n/aexe 00d9fc7c96245227063506e2d338aba139fb1f75c62965ed9115300819566901n/a 
2024-09-28n/aexe 7d252f774409819c5dc82ae7f4788f8c58b1c3c02b551836cbd898105ff3001fn/a 
2024-09-23n/aexe 45f875dde426c2a7bd4cc1debccc69f49554b06d6682b11e1d653a764881d1adn/aLummaStealer