URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/inc/Lu4421.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338515
URL: http://185.215.113.209/inc/Lu4421.exe
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 14:43:04 UTC
Last online:2025-04-28 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 14:44:13 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 19 days, 21 hours, 24 minutes Bad (down since 2025-04-28 12:09:12 UTC)
Tags:185.215.113.16 StealeriumStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-14n/aexe 447765e79de4cd570175406a7d0c4ca1a4a5995d2c75a641223272d7f4845dc1n/a 
2025-01-26n/aexe 2bd8c83b3306aad56b96d731dc2f7d99e75856e6f6a79fb8df769b7273c43addn/a StealeriumStealer
2025-01-25n/aexe 93761d8a6dcbf1a78b5eda2baba1adb18852e3870a4d097f50b5d45d5afecc3en/a 
2025-01-25n/aexe 688dd83aecb3f90672f7924705520c5695fa6a47b32b4fa78ec63622c0c59355n/a 
2024-12-29n/aexe 75cf640396c3aa32bd8012cfe347cc81ab14e814b0fc08724d8fde97ad4ebfc2n/a StealeriumStealer
2024-12-09n/aexe 220c04c30a7dbd084fdebe00102f6340194845d8664dfd669a5549f23a1031c4Virustotal results 32.86% StealeriumStealer