URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/revada/66f45134d0ef8_Advsnced.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3191443
URL: http://147.45.44.104/revada/66f45134d0ef8_Advsnced.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-09-25 20:35:16 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-25 20:36:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:26 days, 19 hours, 47 minutes Bad (down since 2024-10-22 16:23:27 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-22n/aexe eb6fbe066b6ffe71278ae815ae14d551097e0d90beffc8436a5bebbf87250479n/a 
2024-10-18n/aexe b74308854ba5499e7a5c4eeccea21f9f17cd0a20131798ced845359dbe7cb9ban/a 
2024-10-13n/aexe b653b841086203ab5a6f62f5efeff5712707ee632f756d18d34527757337c398n/a 
2024-10-11n/aexe f14be5fc7513bcf0ec5db3c1f3ffcc4d412e86c0c99f8d8695711f206c67999dn/a 
2024-10-10n/aexe da1a79023b4d0dee7a9c99f915ec5b13be9b97f9a42f050e5f7e633859860450n/a 
2024-09-28n/aexe 6b930e5a1b6e07763ec2ee34b77182c58ed66a35405340adf571a4376290beacn/a 
2024-09-25n/aexe 1d1c0eb42525a2caf719f16ff558cb306d4085c20103e6402cd3d58195946d76n/aLummaStealer