URLhaus Database

You are currently viewing the URLhaus database entry for http://jask.powerforxes.shop/yuop/66bf6d1018bb1_deskman.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3212996
URL: http://jask.powerforxes.shop/yuop/66bf6d1018bb1_deskman.exe
URL Status:Offline
Host: jask.powerforxes.shop
Date added:2024-10-04 19:19:57 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 19:20:15 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 22 hours, 12 minutes Bad (down since 2024-10-22 17:33:11 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-19n/aexe f29572a0f435947a8ecbdee035eee2208e39c1b8cfd65f708a7ff080cfda3d52n/a 
2024-10-17n/aexe 4498e3213f270426f181d125c1e57d3fd8749919275d5c10f552c915e07a24e6n/a 
2024-10-15n/aexe 3063cd90784e0f8e64a8cb70f5e4a5432264790512b86d38ed250a0daba3ca7dn/a 
2024-10-14n/aexe cae36f5bc78a7dde2ea8524adb7504e932c0a555d8b86d269e8b9acfab2fb2can/a 
2024-10-13n/aexe 03d657df86f4bbd0b18df0c2a9e5263fec5c25c6c0032f4026ed9da9d1bb4fd2n/a 
2024-10-12n/aexe 8941a91eb1fd4b3f7be855d11c2ac445b8bf5f3690064f1a98b727c0d122757an/a 
2024-10-10n/aexe 41196a37471954e2c7e79e13e0a773f703578c7941e5fb56e88365678242dbban/a 
2024-10-08n/aexe 7584de08ddc0d3a1f9773b3bba4ba739438cdaaf2fcf95e2520e6682ca40daf3n/a 
2024-10-04n/aexe bcad9c21500bf00e52eba9d790a68507d4027eb31a16d40ff41b99de11d7cd54Virustotal results 58.33%LummaStealer