URLhaus Database

You are currently viewing the URLhaus database entry for http://malw.esalesin.com/yuop/66d32ff81a663_lump.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3221176
URL: http://malw.esalesin.com/yuop/66d32ff81a663_lump.exe
URL Status:Offline
Host: malw.esalesin.com
Date added:2024-10-07 18:38:50 UTC
Last online:2024-10-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:39:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:14 days, 18 hours, 28 minutes Bad (down since 2024-10-22 13:07:29 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-21n/aexe 9f60f98d75780d8540ebb8f11306a763b4358d4a1da7d0bab84d098f333f69dfn/a 
2024-10-15n/aexe f14f621b1cb4ca373af1dfb42c088f55c277ff84f8133d5037a013607e82b158n/a 
2024-10-15n/aexe a2fd18a62ac7d7d524e8ab53c4de470cc05c94f9e233b66521a02d8d258397dfn/a 
2024-10-12n/aexe b2aad24c19357a3876f620dacf02c9952de06d3783cc33a4cdf985fc71715724n/a 
2024-10-11n/aexe c145ea8a3c5e15bd6c1c68cebb532da6c9442e6d501c0cfe152481f37fe9cff7n/a 
2024-10-07n/aexe c283cfee5706e6a4a88f851882719751516656aefab8d80fe9a34351ea98a648Virustotal results 73.24%LummaStealer