URLhaus Database

You are currently viewing the URLhaus database entry for http://49.12.117.119/auto/62b7269a5bba1e1025060d4103ce94db/241.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3311715
URL: http://49.12.117.119/auto/62b7269a5bba1e1025060d4103ce94db/241.exe
URL Status:Offline
Host: 49.12.117.119
Date added:2024-11-29 14:47:06 UTC
Last online:2024-12-06 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-11-29 14:48:09 UTC to abuse{at}hetzner[dot]com)
Takedown time:6 days, 17 hours, 55 minutes Bad (down since 2024-12-06 08:43:16 UTC)
Tags:D3fackLoader exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-04n/aexe 60fc2b7de0e9c31478d55a832b5e5d2ad0d4f7cabcdc2b2749fef810c00f1989n/aLummaStealer
2024-12-03n/aexe c6f114c1e8044aae5362b3bf61845f46c7cc6ee23ac9eba89c8dd0977ea806e9n/a LummaStealer
2024-12-02n/aexe 07763c6456f63493cb1fa4392860d564e687b3c246b4938795d0afea43221d00n/aLummaStealer
2024-12-01n/aexe 7989fb637d1e8268371bafe31a452bb626abaae2345a9ff5838a258109e91f04n/a LummaStealer
2024-11-30n/aexe 15d0fbb727261c4dd005ebbc323949aba6afd46840a57a46a058fe8633bd00dcn/a 
2024-11-29n/aexe 6bde8e2597db103249ee066b1b81fa21cdd96b866ff6e640a87e7ebb92118bfen/a