URLhaus Database

You are currently viewing the URLhaus database entry for https://docshare.icu/templates/imagesoftware/ImageEditorforWP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3423977
URL: https://docshare.icu/templates/imagesoftware/ImageEditorforWP.exe
URL Status:Offline
Host: docshare.icu
Date added:2025-02-02 07:34:07 UTC
Last online:2025-02-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-02-02 07:35:05 UTC to abuse{at}globaldata-cloud[dot]com)
Takedown time:1 day, 14 hours, 14 minutes Poor (down since 2025-02-03 21:49:37 UTC)
Tags:exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-03n/aexe e23d5adb5b14436e7d60b3f7e8994333af77f807cdeb28ea7df43852824a7a77n/a LummaStealer
2025-02-03n/aexe b109e1eae39bf683262796857e65e71a70deb76ab500fb103a4f743d9884df32n/a LummaStealer
2025-02-03n/aexe 0c3d32d400410ab104b0446ecd9be7bfd63556265a2fad2edf5cec68d36aa1e1n/a LummaStealer
2025-02-03n/aexe 0f70ecaa27b159fec96e2a0e3a2080a186f080dd0e4416ab7f240517264056b4n/a LummaStealer
2025-02-03n/aexe 07ab5f1fcaa448d0679efabd38bf4fef686f6c203588c40af888a1130ba954den/a LummaStealer
2025-02-03n/aexe 48d334a86cfc76551632483b6337278e757ce0e8b0f0086d9010bb37ae14d469n/a LummaStealer
2025-02-03n/aexe 6fc945523cc89d3a2f3abf600117a4abe52f4f7f7e22ecb763566c147e8e59bdn/a LummaStealer
2025-02-03n/aexe 3798943b9e4e28bf796e4dd28a17cb0ccca344c2b0f2473710149059e981ae84n/a LummaStealer
2025-02-03n/aexe 24d72a9d0bbef0ad3c845b1fee3854f401771f3925587264bfcd36b4ddcaa994n/a LummaStealer
2025-02-03n/aexe d28c69e931b6bf364fab0116583f80a3243d12ad870d8580abe8f2cdc2ec1c7bn/a LummaStealer
2025-02-02n/aexe 66e610fd6a77a7e73b5fcfbc2f741215989fc6a66d483da9805d197288a0b387n/a LummaStealer
2025-02-02n/aexe dd18b6c20deb7a5ef80c8b9a3c9e60e73e5f002422743641a02badfa66241cb2n/a LummaStealer
2025-02-02n/aexe 2c669ce4a14cb9a54ea4c4c9aad86c4be8ef2fa77df7515930ff588eb85adccen/a LummaStealer
2025-02-02n/aexe bd37c06dd246a70a7f3d34e939f9d9016884c0d09fe835622c8f130b948170b4n/aLummaStealer
2025-02-02n/aexe c1e01e2b2769898b635f38646ee2481000b43f8fe5d0efa32cdc13faf6e9e31fn/a LummaStealer
2025-02-02n/aexe 567e12bf3b85bf8c13d9e7deaa5f5ce636658a34d1a4f2389b6094714b26850en/aLummaStealer
2025-02-02n/aexe d46662f5f75e5ae182f522a1e64df9bade5cdc5d7eca415062aa2af2c4b60853n/aLummaStealer