URLhaus Database

You are currently viewing the URLhaus database entry for http://app.rtpdgox.info/css/0a839761915d.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3231057
URL: http://app.rtpdgox.info/css/0a839761915d.exe
URL Status:Offline
Host: app.rtpdgox.info
Date added:2024-10-12 04:49:09 UTC
Last online:2024-10-18 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-10-12 04:50:16 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:5 days, 22 hours, 25 minutes Bad (down since 2024-10-18 03:15:37 UTC)
Tags:32 exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-13n/aexe df708669748da15221b332a5333132c5d04adf1d1efcd2c0f01092fadaf87507n/a LummaStealer
2024-10-13n/aexe 604aa4c66702122708d2f539329af653c9f0b3b231aefe52f9343f9650ed0133n/a 
2024-10-13n/aexe dfe63c640589833895d89ceeb2b9e1a34bc3cb747712ebabcb46fe61c54138f8n/a 
2024-10-13n/aexe cc5cc57209ea3ad2552fed7429e10ed5e592c2e4d130a4d698ed3995d90a8f7cn/a 
2024-10-13n/aexe 6ad3d3aed964bce74d1fac7a1856eddbd84e26b510cf89ceab24580ce78ac5a4n/a 
2024-10-12n/aexe 880c7ee9b5f06130d090b2ebfccd73e7127e1b605db2a3a84da2ac7923d4a0c2n/a 
2024-10-12n/aexe 176a8d1f95a48e830511b3b71b7072ff88d8ac34c5b9ca4aeade832101360cfbVirustotal results 24.66% 
2024-10-12n/aexe 6491d7f9887c119e17104f3145693089b1c83c217a7616a31b219154f8794b0cn/a 
2024-10-12n/aexe bb13b8d854de9343d4954d773416ccbe720ed09a6bd6221fb23f8f22c974a1e6n/a 
2024-10-12n/aexe a460c28ef668daa443793a4a85494c0cd7da29f8a4148581515dc786d6fe4789n/a LummaStealer
2024-10-12n/aexe 435b15850018c02df0118f5f03175daf2c9428333a210e70b8b496b563509012n/a LummaStealer
2024-10-12n/aexe a2d2d18d0327596f73814cc6bdf9954e76716987418362879710c58a3f6c6eedVirustotal results 34.72%LummaStealer
2024-10-12n/aexe 5744877c48b6e0cb978299855f06eaea0724e66667871756b04ee19f75486026Virustotal results 35.62%LummaStealer