URLhaus Database

You are currently viewing the URLhaus database entry for http://jask.powerforxes.shop/yuop/66b274e0e1b95_shapr3D.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3212979
URL: http://jask.powerforxes.shop/yuop/66b274e0e1b95_shapr3D.exe
URL Status:Offline
Host: jask.powerforxes.shop
Date added:2024-10-04 19:19:50 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 19:20:15 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 21 hours, 38 minutes Bad (down since 2024-10-22 16:58:58 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-19n/aexe be87bace6cb5823cf171b4db13f512e75ad12cee3a91472ffb5d5bfb76438b2fn/a 
2024-10-17n/aexe 0cc8cca16c0e874259a7da41a0e77afb2324465ef4b12ca2b28d9e0af69c5284n/a 
2024-10-14n/aexe 819645fbcbc8e4ea4ec9cd20219b6672758c668e181e8224ecba538d9977edc1n/a 
2024-10-13n/aexe c989235251624474b3984c99c5018c0bd090f513e19cba9fb97593c91286b2c4n/a 
2024-10-09n/aexe 3d34e772cf446176ae83dd27c64f92588875743af4f102a6d1f337ab57f6cdb4n/a 
2024-10-09n/aexe 7f673e372f6da6b9deccf048f5b115dadc2d7a6a584ecd1bfba1c4976b7074b0n/a 
2024-10-04n/aexe fc678f0540da23c49928f774b88856d297ae5732f48e154279a78da2ff4af566Virustotal results 76.39%LummaStealer