URLhaus Database

You are currently viewing the URLhaus database entry for http://playd.healthnlife.pk/ldms/0a839761915d.exe#t_up which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3208602
URL: http://playd.healthnlife.pk/ldms/0a839761915d.exe#t_up
URL Status:Offline
Host: playd.healthnlife.pk
Date added:2024-10-03 18:57:07 UTC
Last online:2024-10-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: aachum
Abuse complaint sent (?): Yes (2024-10-03 18:58:11 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:13 hours, 31 minutes Good (down since 2024-10-04 08:29:36 UTC)
Tags:dropped-by-PrivateLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe 02455ba4c23ad3cbf1deac24b42545f4cd16c3039e68f41b5b2cb4858a82db83n/a 
2024-10-04n/aexe 17dfc8b6367dc3b0388635ca0aaf0bdc74bae4e67dd6e70b2a710fc142b08b86n/a 
2024-10-04n/aexe 2b6e172ad598fc835f1f3f7f8f598834313419d07f6718915e72324cd2bacef9n/a 
2024-10-04n/aexe bdf7dc31da2a3c352fb25120b07684b30c747aed04ac960376024924fcc15dd8n/a 
2024-10-03n/aexe be7bd42c8c241efa7e414ab3596bd3421062efe0b7fc70386d8f816226ebb1b4n/a 
2024-10-03n/aexe 18a1c19520056c703e08601f871a4d61b7feb8adeb577bbe470329c3d1a3bd24n/a 
2024-10-03n/aexe 4b922049e6d164273c8a65da6c31e1f41e1e0a5d821a7aab0fb512e14906dfc9Virustotal results 32.86%LummaStealer