URLhaus Database

You are currently viewing the URLhaus database entry for http://proxy.amazonscouts.com/ldms/9dd06d870941.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3223816
URL: http://proxy.amazonscouts.com/ldms/9dd06d870941.exe
URL Status:Offline
Host: proxy.amazonscouts.com
Date added:2024-10-07 19:17:11 UTC
Last online:2024-10-12 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 19:18:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:4 days, 22 hours, 46 minutes Bad (down since 2024-10-12 18:04:40 UTC)
Tags:LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-09n/aexe 743066ea0e49b30514250a6cf9a6b948448bfbcd33736f86a9ce5bfca5742dfen/a 
2024-10-09n/aexe eac4a4c26502159bb5547be88595ed2cb526cf8af62b91c59d420698253919bfn/a 
2024-10-09n/aexe 3295863006af2db31482e81e08bc048a1db976c138ee7a9794f2777bd361ee1an/a 
2024-10-09n/aexe c5584fe00bcd34f9a44bca7fc3a44aba589ebbf20e886251a25d68a493091cc0n/a 
2024-10-08n/aexe 9ddd133b83b62297dff92e701e0d7a769f42dc59255f98021914b4f7ee6e5c56n/a 
2024-10-08n/aexe 4bd55d9184f65271514cb0d9e25e97831d2c46ef367b3a3e2c223b49001af26fn/a 
2024-10-08n/aexe e9073ec347567724fab45e3c8ecceddb3bb5cb362a9badfd4cc1aae8971a79cfn/a 
2024-10-08n/aexe 59f93df8c5a2db88950e25d1c201fd30491e7340f7bcc0e791cfe157352a0383n/a LummaStealer
2024-10-08n/aexe 7a947f2289a0cb63b5dae2f4409db33fd73655f2102193b2f8b2e2bd75879bf7n/a LummaStealer
2024-10-08n/aexe 86f3cf56f2503affb62ea5342087be7e9fbb2da366ec5e95f70bb2c196543b93n/a LummaStealer
2024-10-08n/aexe 149d37e3741ea4b536725e5f98dae7505038856f0aec1ebfc16c47e20cf274c6n/a LummaStealer
2024-10-08n/aexe 7dc3d6e633cbabe95c39fa36f94ab6657e3c04dab7a9a6c1f79c9e2424378e00Virustotal results 44.44%Vidar
2024-10-07n/aexe a975228ff3dd9eac2caa7ee214ae3a13abb605f72b12dc9000426b2a4b57c538n/a LummaStealer
2024-10-07n/aexe f9de78505c86a83088e5a02f71e0940cb7b6a5f7302b8da191755dc1d5490ad2n/a LummaStealer