URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.12/files/fate/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3346459
URL: http://31.41.244.12/files/fate/random.exe
URL Status:Offline
Host: 31.41.244.12
Date added:2024-12-12 15:33:23 UTC
Last online:2025-01-15 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-12 15:34:18 UTC to dl{at}redbytes[dot]ru)
Takedown time:1 month, 3 days, 17 hours, 58 minutes Bad (down since 2025-01-15 09:33:04 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-11n/aexe d5a861959e92c8a53a516c7438448396e7e433866488b01eba69354897ed5417Virustotal results 52.78% LummaStealer
2025-01-08n/aexe 9d67ff908523557bff4d40db2348e83bcebf0fb4acb054ac900c823f2f460da2Virustotal results 48.61% 
2025-01-05n/aexe 558fe8c705bbd035f886cc02acee3fdfa50398e74795f62d182e01225d58e2e2n/a LummaStealer
2025-01-02n/aexe f2ba7fef4111f604b3624c0418c6c92adbc343300de7075c834479d3a1bd914bVirustotal results 40.28% LummaStealer
2024-12-23n/aexe 49bfa0b1c3553208e59b6b881a58c94bb4aa3d09e51c3f510f207b7b24675864Virustotal results 34.29%LummaStealer
2024-12-17n/aexe c6491d7a6d70c7c51baca7436464667b4894e4989fa7c5e05068dde4699e1cbfn/aLummaStealer
2024-12-12n/aexe 9597798f7789adc29fbe97707b1bd8ca913c4d5861b0ad4fdd6b913af7c7a8e2Virustotal results 41.67%LummaStealer