URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.75/files/7868598855/DTQCxXZ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3438183
URL: http://185.215.113.75/files/7868598855/DTQCxXZ.exe
URL Status:Offline
Host: 185.215.113.75
Date added:2025-02-13 06:51:07 UTC
Last online:2025-02-22 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: aachum
Abuse complaint sent (?): Yes (2025-02-13 06:52:06 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:9 days, 7 hours, 13 minutes Bad (down since 2025-02-22 14:06:04 UTC)
Tags:dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-20n/aexe 6b40ec300fe125ec462e6f24501c0664e9b5a74c1d225ed0c361b24d49775890n/a LummaStealer
2025-02-17n/aexe e6a4ff786a627dd0b763ccfc8922d2f29b55d9e2f3aa7d1ea9452394a69b9f40n/a LummaStealer
2025-02-14n/aexe 4411bda3e930ffbe7fb100c2cba4c2a2833f6066e5f1a36b347fa26a82279505n/a LummaStealer
2025-02-13n/aexe 288257937f865239730f9bb64946e6ce3e0c547027f31b900f4e94529126e2c6Virustotal results 63.38%LummaStealer