URLhaus Database

You are currently viewing the URLhaus database entry for http://malw.esalesin.com/ldms/fedf8679e8d2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3222195
URL: http://malw.esalesin.com/ldms/fedf8679e8d2.exe
URL Status:Offline
Host: malw.esalesin.com
Date added:2024-10-07 18:51:31 UTC
Last online:2024-10-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:52:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:5 days, 1 hours, 50 minutes Bad (down since 2024-10-12 20:42:48 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 6b032a89988a3de8005371562c8d89e1e951171eb84e40eaecf718a5a1b944f9n/a 
2024-10-09n/aexe a69ad94d546b85d0a5eb3b92c5d5c9ee115f3cfe8d457f5c346e34b1eceeb44an/a 
2024-10-08n/aexe 4e279b8a2d0b73cc8b05409ddb909f4e5f3df19a23fc2fc82cebb473fe204261n/a 
2024-10-08n/aexe b93411d14ce390b15de4a90cc64322bb5051f2289717949a45a07e61890d4aban/a 
2024-10-08n/aexe 4d198089c44d6c229906a7d268dc540aa1d3aaf46bad1fc01be48b4d7d8e4e8bn/a 
2024-10-08n/aexe ae925cbddc9cc9006173736c8bb083f9029c73fb5e8f4f335d2eaa62e01ab23bn/a 
2024-10-08n/aexe 21722552bf3df1eb25d109053c2c7af03cb7029fd3596bfdf76e9fe5f49273c5n/a LummaStealer
2024-10-08n/aexe df08d820e0bffbed4e2cdb1fd08ebffbbe7bc6a9983057b0ff58eafb1e2db197n/a LummaStealer
2024-10-08n/aexe 9ac8e5087032a4ff9eebe07dfc44668db4acf4822ff6257e3c8cab0d5e656af2n/a LummaStealer
2024-10-08n/aexe 843530ab613b2fd9b5f8af617a5e115d293d4456b1f0cc637141b5a53bee6f14n/a LummaStealer
2024-10-08n/aexe c1825014c69aa430f2c108e0ab1ed9e13225230e0ab52a435dd578991a901a5bn/a LummaStealer
2024-10-07n/aexe dffda48740b0625c2f9b24f5019590608b7dbe67cc4903431023b406ecf924c4n/a LummaStealer