URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.75/files/fate/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3435919
URL: http://185.215.113.75/files/fate/random.exe
URL Status:Offline
Host: 185.215.113.75
Date added:2025-02-11 08:42:08 UTC
Last online:2025-02-25 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-02-11 08:43:05 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:14 days, 8 hours, 38 minutes Bad (down since 2025-02-25 17:21:47 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-22n/aexe 5654aa0407c06a1dd21ad9c169b082683297b32a967bbd5cef28bb935f1885c7n/a 
2025-02-20n/aexe 0049db5a9a2e97c4878b2c2185c88ed3c27336b244e8232558bc4d25e6579a90n/a 
2025-02-18n/aexe 906bba1ebdb3cb9cc5840fda24e9c0c9147e779e1ecf479910d04b6ef5588bd1Virustotal results 52.78% 
2025-02-17n/aexe 713e92e6b5f368bb1208f55f80a3353f8ffa25a97f914fad517032bf923782c9Virustotal results 35.21% 
2025-02-16n/aexe 6c10468ad2fc3e51d3599df5d43b2a06f0781a6594f4119a8bb9b4495aaa76ecn/a LummaStealer
2025-02-14n/aexe 268ab7cd89f77eb147718766428f4ea5dd4e54af254fd9b8892e95a0c5d9597fn/aLummaStealer
2025-02-13n/aexe 7de410e0adcd567443a552a7b79cac1dc5d1a5e228cd05f8b8e9c36187e04c5bn/a LummaStealer
2025-02-11n/aexe 4470809cd7fa85c0f027a97bf4c59800331d84c4fc08e88b790df3fbf55042edVirustotal results 48.61% LummaStealer
2025-02-11n/aexe 3ea9ea6d01e80568586120facc27bb2c31923d3bdcb9427cce6c458c6c6e3935Virustotal results 79.17%LummaStealer