URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.97/files/6691015685/Bjkm5hE.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3432215
URL: http://185.215.113.97/files/6691015685/Bjkm5hE.exe
URL Status:Offline
Host: 185.215.113.97
Date added:2025-02-08 17:29:07 UTC
Last online:2025-02-22 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-02-08 17:30:10 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:13 days, 20 hours, 58 minutes Bad (down since 2025-02-22 14:28:21 UTC)
Tags:exe LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-16n/aexe 4287dfb79a5b2caa651649343e65cdd15c440d67e006c707a68e6a49697f9f33n/a LummaStealer
2025-02-14n/aexe 6ed10724e16af4c6860476e695e0764a418da29f9f7f73bdc7bcd3c2db9451d3n/aLummaStealer
2025-02-13n/aexe b8f2fcb398300d4919a83e210ddca34e07e9a23f5c43bcc88224d37c2187b368n/a 
2025-02-13n/aexe f74049ce70901c7d3d397bfd04973a0d9dcc164efdc14291f0a4f95a0d173076Virustotal results 45.83% 
2025-02-08n/aexe 8afc16be658f69754cc0654864ffed46c97a7558db0c39e0f2d5b870c1ff6e39Virustotal results 72.86%Vidar