URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/yuop/66f5a53dda014_crypt.exe#es which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3193004
URL: http://147.45.44.104/yuop/66f5a53dda014_crypt.exe#es
URL Status:Offline
Host: 147.45.44.104
Date added:2024-09-26 19:05:13 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-26 19:06:08 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:25 days, 21 hours, 32 minutes Bad (down since 2024-10-22 16:38:29 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-20n/aexe c5ba1907cf5a897483cde1e82f55a6026fe2783b39a8ef388828ebc4fd36ceean/a LummaStealer
2024-10-12n/aexe a7fbb5a4e0eabe11136e22db47a71c3c7e5942a9f1f68a6a7d3bf280cec91df0n/a LummaStealer
2024-10-06n/aexe 4014462837de1aaa5f81ff27ae9b54659543ceb7457737943c5f6dc7ca6f70b8n/a LummaStealer
2024-09-30n/aexe 379eb52bc28ee97828786b4fbcb46c2ca238fa7f812ca012752bf9a78d21fbebn/a LummaStealer
2024-09-28n/aexe 2e81f9e33108842298e7673f6bb0a893b7294478bc03963cd990e31ba6861060n/a LummaStealer
2024-09-28n/aexe d7f4e5aa99bad56aeb8f88c9239a65d368875cb870a429cfecd546f6ed35aa3fn/a 
2024-09-26n/aexe e2a2430866d3186a75e84da8443e4b306aaa91527e4e8856c1a7f7e217aade81n/aLummaStealer