URLhaus Database

You are currently viewing the URLhaus database entry for http://nsdm.cumpar-auto-orice-tip.ro/ldms/7f3c2473d1e6.exe#sp_vid which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3219204
URL: http://nsdm.cumpar-auto-orice-tip.ro/ldms/7f3c2473d1e6.exe#sp_vid
URL Status:Offline
Host: nsdm.cumpar-auto-orice-tip.ro
Date added:2024-10-07 15:22:04 UTC
Last online:2024-10-09 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-07 15:23:08 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:1 day, 21 hours, 32 minutes Poor (down since 2024-10-09 12:55:52 UTC)
Tags:dropped-by-PrivateLoader LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 53e0a2da42ca576d96a70ce70f1b1817230456a4e66e6ae58ed4167c260be391n/a 
2024-10-09n/aexe 8c3d02cd4f4595f744105b1a6cda6d041362f5df346a7a4e09aa392f88722314n/a 
2024-10-09n/aexe 931002b6e93491b8899d95effe0ef45f3bb2aa95f048ce85afda9eef881cdfcan/a 
2024-10-08n/aexe 0783750670789c42fbaf67d7c8035743d1047ecc2929f1bcdfe6cac51453f709n/a 
2024-10-08n/aexe 3f787c907d4a0a8924f9753666e5205c8fe943821b308fee58d7f9dc3db88c7bn/a 
2024-10-08n/aexe d3cc21a846a0334c27c0258435c51483021df14e0d06227a05570abb9f62ed19n/a 
2024-10-08n/aexe 2efbe99eaff294a4ee41b922098c0ae2eeba044cc2f9fbc5586a620c2ceadc93n/a 
2024-10-08n/aexe ba597f8f0f95b56a8150028b10437ddf422256c6e6ae7f3b49a0da28fe08deeaVirustotal results 21.92% 
2024-10-08n/aexe 75ace186e575acce943e9711bddc6cbc3c7a50c6ac1f7071ab1335639f991e50n/a LummaStealer
2024-10-08n/aexe a2c8f7d7fd7981abfdfe8aecdea75fae2b0deba35bada15e36776624738d61e0n/a LummaStealer
2024-10-08n/aexe 9fd632a5a857337a3c2cc53a566348b1316af37c9f59f9ed18394a54d916a54dn/a LummaStealer
2024-10-08n/aexe edbaedae0848ec8f83170d81fc0786d6a51eeedc524d95020490f4b0a516e575n/a LummaStealer
2024-10-08n/aexe f304d78842e490fcf45b04ef0f068aa28a20781f1d4604f00ae7fd563419039fn/a LummaStealer
2024-10-07n/aexe 28e5db508bbc80a7d9e5900aeb15d8eab24e241dd1e9279abb618fe980672375n/a LummaStealer
2024-10-07n/aexe 7823532217e8b06b102734023019188833b3e0ae711c3dc6f9cb437d8c48d14bVirustotal results 45.71%Vidar
2024-10-07n/aexe 2bda40435881101ace72e48ffcc04afa3e5ca6e9e6caf79b0a5a132840152adan/aVidar