URLhaus Database

You are currently viewing the URLhaus database entry for http://malw.esalesin.com/yuop/66bf6d1018bb1_deskman.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3222267
URL: http://malw.esalesin.com/yuop/66bf6d1018bb1_deskman.exe
URL Status:Offline
Host: malw.esalesin.com
Date added:2024-10-07 18:52:27 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 18:53:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:14 days, 22 hours, 18 minutes Bad (down since 2024-10-22 17:11:40 UTC)
Tags:GoInjector LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-21n/aexe 674c13d574e6db85eb8045cbcdf599341a628482723e32fb4db44d76e23eee57n/a 
2024-10-20n/aexe 238084dbd0360bd4c2e0d536393c7f0cf96bed830729b213d1aff89e7ea539f9n/a 
2024-10-18n/aexe d056396d6f22b359608167e6822b1c01a51fbde098ba43276246cdd1fc53e9a1n/aGoInjector
2024-10-14n/aexe 9e7324e93cd89c738ef6c9b14c846141ad071cce52abe49e84192552f000b012n/a 
2024-10-13n/aexe 134ef2191dcb28237f943db18ac5d4e281d13d0be9544c979377ca7cdf8dcaben/a 
2024-10-12n/aexe 89e9c5a78085fd12780c3929c21c1d49a8da01bbdf405f4c1053f264f4720639n/a 
2024-10-09n/aexe 5120c6221c6c30cfef89db9fa2171a85af771b697e611d2b439045ad6941d0b7n/a 
2024-10-07n/aexe bcad9c21500bf00e52eba9d790a68507d4027eb31a16d40ff41b99de11d7cd54Virustotal results 60.56%LummaStealer