URLhaus Database

You are currently viewing the URLhaus database entry for http://malw.esalesin.com/ldms/04a4f32fae41.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3221339
URL: http://malw.esalesin.com/ldms/04a4f32fae41.exe
URL Status:Offline
Host: malw.esalesin.com
Date added:2024-10-07 18:41:16 UTC
Last online:2024-10-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:42:08 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:5 days, 0 hours, 35 minutes Bad (down since 2024-10-12 19:17:14 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 48c9e1cce6868ed1f46051b8898643c59545185e16600f15bd54ce86a74f766aVirustotal results 30.56% 
2024-10-09n/aexe 6091ed0ebef8b9521789423353b160e92490b4aaf0210d2f662f6cddecd60bdfn/a 
2024-10-09n/aexe 59052b00e8a9f39403f0a6721bb7f7cf6f642ac1bb1f3b33a5181bfbe1f811dcn/a 
2024-10-09n/aexe 3cb2802eef6f49e7f60f7609f21cd840159d47199858bf6dbf5695e33c6600aan/a 
2024-10-08n/aexe bbfe361a90489fa7a5e7bb26e8b258046fb54d27c3dc2e793fc940404588ff10n/a 
2024-10-08n/aexe ed4a142de5a299d7b02841310ae2f18e00007344694a8b5fa2910f7ea42c00d8n/a 
2024-10-08n/aexe e683c235ddaac34e07796c1ac582e2c2c9a40079c2b89625b507f64cbc90d1e9n/a 
2024-10-08n/aexe 9e7d22a7d2f77fdf350e2ea124836648046f4cc2de5c41562577dc91c34c7b49n/a 
2024-10-08n/aexe 92aa6ba3c5cfa7cfcc37532f7013b82c1e9d42b9ed04d1a7194cb910eb7c6e73n/a LummaStealer
2024-10-08n/aexe e66b9d51c08c1338d7ed7ed861bbddea77f64daf96e7ed78d4a0315cf2c43fb5Virustotal results 50.70% LummaStealer
2024-10-08n/aexe 1529baa44cb500aa37c71ff885c8e6379a46cf1015f6ab33b93a914c7c42209fn/a LummaStealer
2024-10-08n/aexe 0d2d7b67867e49a293adc42e9fbd0bf60313a0583e3f258ca6b21fa86109f434Virustotal results 50.00% LummaStealer
2024-10-08n/aexe 528165c02af47385f8b0016d580295bbd8dc1d71c6436d4d7be4648b2b9e36f0n/a LummaStealer
2024-10-07n/aexe 669520f903f4178a0b5365327369eab98a3e595dddcf1164324beeae8fca8b0cn/a LummaStealer
2024-10-07n/aexe c3353ac5641f21e195cc2018392c516fbe1d9886b4e3113d3e4b6ff1cea7758en/a LummaStealer