URLhaus Database

You are currently viewing the URLhaus database entry for http://hans.uniformeslaamistad.com/yuop/66bf6d1018bb1_deskman.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3211584
URL: http://hans.uniformeslaamistad.com/yuop/66bf6d1018bb1_deskman.exe
URL Status:Offline
Host: hans.uniformeslaamistad.com
Date added:2024-10-04 18:53:25 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 18:54:09 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 22 hours, 19 minutes Bad (down since 2024-10-22 17:14:02 UTC)
Tags:exe GoInjector LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-18n/aexe 6387722410c19553edfab90f3b8e0855c20165eccbd25b79f2abf3dbcc3d7707n/a 
2024-10-16n/aexe d28e9d1ff8c60ad7294222f62bbc7db52e683d6eb4c26efb9f15bf25cfb8ede2n/a
2024-10-14n/aexe 47a8ebeea36e43e081af8422869b04b341729f20e813777617baedabb220862fn/a 
2024-10-13n/aexe faf77292c608f3dd3ed9a24f4ff38737ebbb48f58bf57f419c991cc1bf8a7563n/a 
2024-10-12n/aexe ff9041d3e2cc41f134b5fbabe244251fcbe9b83e4a5aaed2eb5b93efdd6dccc3n/a GoInjector
2024-10-11n/aexe f2bc97fdf7197d53f0fab7649b5cf5e78e1fbd17d18f05bc8ebd1b7e51607ad6n/a 
2024-10-05n/aexe e2863af200db0dab73a22cf969399ef9127d0c309f0de1411f02a0df787bd8bbn/a 
2024-10-04n/aexe bcad9c21500bf00e52eba9d790a68507d4027eb31a16d40ff41b99de11d7cd54Virustotal results 58.33%LummaStealer