URLhaus Database

You are currently viewing the URLhaus database entry for http://176.113.115.7/files/7481626938/MCxU5Fj.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3460094
URL: http://176.113.115.7/files/7481626938/MCxU5Fj.exe
URL Status:Offline
Host: 176.113.115.7
Date added:2025-02-27 19:24:04 UTC
Last online:2025-03-07 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-02-27 19:25:07 UTC to abuse{at}starcrecium[dot]com)
Takedown time:8 days, 0 hours, 14 minutes Bad (down since 2025-03-07 19:39:40 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-04n/aexe 7a87b801af709e8e510140f0f9523057793e7883ec2b6a4eab90fcf0ec20fd4an/aLummaStealer
2025-03-02n/aexe 318e51dffbc41fc6f09fd5bf997830e90d52dab272fbfdce80dc03ef94fe7a14n/a LummaStealer
2025-03-01n/aexe 10a04ab9c631621719b2446353b01e0d761d325f126ce42e7ec7686c80437b0cn/a 
2025-02-28n/aexe cb0e213d58e7f0dd47990662f799e85efbce97dc17da9dd58f35e7b9ac8ed750n/aLummaStealer
2025-02-27n/aexe a1d5f24220948a932a2847df4744c2318322ee6408bf73ca37d71787d67d7529n/aLummaStealer