URLhaus Database

You are currently viewing the URLhaus database entry for http://book.rollingvideogames.com/temp/lem.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3449968
URL: http://book.rollingvideogames.com/temp/lem.exe
URL Status:Offline
Host: book.rollingvideogames.com
Date added:2025-02-23 15:03:11 UTC
Last online:2025-03-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-02-23 15:04:04 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:16 days, 18 hours, 7 minutes Bad (down since 2025-03-12 09:11:51 UTC)
Tags:Adware.Generic exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-05n/aexe a7b35988614824b602540fa1ee9279941b38a10a5890d6ba3b5cf1a86c265074n/a 
2025-02-28n/aexe 660efee203162be2b9ae61d83fdb8291c2f4ec9b473108f2eacbdd060d088aabVirustotal results 61.11% 
2025-02-27n/aexe e34756a5015b227ce85128b38185cc0eb54a9ee92b06337aaa77bd033c7e3c9dVirustotal results 15.28% 
2025-02-23n/aexe 62c09b2435ff52e29a56f8474f6307084383d73ecbf5dc62bd9767a23d50ec39Virustotal results 41.89%Adware.Generic