URLhaus Database

You are currently viewing the URLhaus database entry for http://malw.esalesin.com/ldms/7f3c2473d1e6.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3222016
URL: http://malw.esalesin.com/ldms/7f3c2473d1e6.exe
URL Status:Offline
Host: malw.esalesin.com
Date added:2024-10-07 18:49:09 UTC
Last online:2024-10-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:50:14 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:5 days, 1 hours, 38 minutes Bad (down since 2024-10-12 20:28:30 UTC)
Tags:LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 53e0a2da42ca576d96a70ce70f1b1817230456a4e66e6ae58ed4167c260be391n/a 
2024-10-09n/aexe 931002b6e93491b8899d95effe0ef45f3bb2aa95f048ce85afda9eef881cdfcan/a 
2024-10-09n/aexe 6727476baca4acfa82920ef3bc360a300bf5137791ebcf6d195a852a37bceca4n/a 
2024-10-08n/aexe 0ab373bebeb1ad02c95c0517983a6c5e0d61a781548f9542101088cebfd328aen/a 
2024-10-08n/aexe 53c454d3daba412d544f91eddec97c12c12f0b16aa1aa1595527be78210fbfcfn/aVidar
2024-10-08n/aexe 6855feaad22b9fab33f782a030dca8efeceb300eb547e0a9ce5cb36520f1bddcn/aVidar
2024-10-08n/aexe 758899ad43aea7a53b7d397c517773e712e7ed0f66f8cbd52bfd39a04aabb3d0n/a 
2024-10-08n/aexe f76e79c5e64a9d070fad62850774c0110ec1340fa83268acc6163491e138e5aan/a LummaStealer
2024-10-08n/aexe 85c5eb205bffaa98daaa261a17c8f38e13b0fb2fc0e012ffa19af3d4ab6b4813n/a LummaStealer
2024-10-08n/aexe a2c8f7d7fd7981abfdfe8aecdea75fae2b0deba35bada15e36776624738d61e0n/a LummaStealer
2024-10-08n/aexe c75c774f41ba9b7c18a9c4ccd2c34dc9afd839dcc2676a11c59bd823c999ba5bn/a LummaStealer
2024-10-08n/aexe 3823cd50405fb49bc84f74fd757610e11d7e0fc25c6933a7e4d90d6e98bf8defVirustotal results 44.44% LummaStealer
2024-10-08n/aexe b205b92c24af56a9410723c0ca91c554388a7c72227522399b8747a8bda1e97bn/a LummaStealer
2024-10-07n/aexe d6a1efbe54ac13744f8f8a91ce3600d576fd5751684cb14a904291dcacdfcfc1n/a LummaStealer
2024-10-07n/aexe f0a8b069fdf150662ff44789cf2850b9c416e1be736f13f66111ebf2e2f7cd6fn/a LummaStealer