URLhaus Database

You are currently viewing the URLhaus database entry for http://yowui.johnmccrea.com/ldms/956d73b7f041.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3221242
URL: http://yowui.johnmccrea.com/ldms/956d73b7f041.exe
URL Status:Offline
Host: yowui.johnmccrea.com
Date added:2024-10-07 18:39:53 UTC
Last online:2024-10-09 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:40:16 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:1 day, 21 hours, 9 minutes Poor (down since 2024-10-09 15:49:56 UTC)
Tags:LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 50ceb67e5a65b823aae5f46619a22c70ee8bd3a9629cae0f2057dc910a833d06Virustotal results 30.56% 
2024-10-09n/aexe 0c9bd35dacf89f8fddea89fb89d6019bca37b308365a78234fd56a57260e87d6n/a 
2024-10-09n/aexe 4533fc67463d0beb908ebc5e31d74c3908a71ea1c90955454323b1ffc43843f0n/a 
2024-10-09n/aexe 126068092483444ed45ee141e4a7f6fc5ecda4a59444495501b645eea4fb61fbn/a 
2024-10-08n/aexe afd77bb27473f845380d50bda07549f7cf919d42723a6bb11fe7e4c1f3294c76n/a 
2024-10-08n/aexe 7f831f3a7c0129710227f5aa73b640733b81c84a0c1007ef1cef440cf8bb3441n/a 
2024-10-08n/aexe 1575c0c693a457a3cfbf2fe983d0aea65e45397ba15d3ba65ce2d505907f2b68n/a 
2024-10-08n/aexe 47a785933d7812598561df1915070c4e96d23708fd28cec84d6794a105e68c22n/a 
2024-10-08n/aexe 06921efeedd768d9d69a55933c0e54801c0378061c8fcb6b5a0334cbfc9c4af9n/a LummaStealer
2024-10-08n/aexe 26a3d2e19923fa4d7020d42680f3d96715ba62d6102731fd646c0889a818f316n/a LummaStealer
2024-10-08n/aexe f2f1a93d30d38fbe7b271d9c9b173b18b98e32c3424e62808112411fb05c32b7Virustotal results 44.44%Stealc
2024-10-07n/aexe f1f1e532ccc327d4f648bc4c249fbad7056414b137e036bc4011f1583cc5d1f6Virustotal results 40.85% LummaStealer
2024-10-07n/aexe 57e369bd535e128f9290073985cd2a26b267e81f4c26621b0266402f07018595n/a LummaStealer
2024-10-07n/aexe 9e97f0139c2d9200e07f918a140e0d6952deff70ec218fe861ef0ba73d4f786fn/a LummaStealer
2024-10-07n/aexe 317a0b9ed2e3f33dd13ddb5efdf8dadeb9ceb2ef9ea9dc097240fcf67a91c6dfn/a LummaStealer