URLhaus Database

You are currently viewing the URLhaus database entry for http://176.113.115.7/files/7868598855/zY9sqWs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3467522
URL: http://176.113.115.7/files/7868598855/zY9sqWs.exe
URL Status:Offline
Host: 176.113.115.7
Date added:2025-03-05 06:31:46 UTC
Last online:2025-03-21 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-05 06:32:26 UTC to abuse{at}starcrecium[dot]com)
Takedown time:16 days, 0 hours, 35 minutes Bad (down since 2025-03-21 07:07:52 UTC)
Tags:Amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-20n/aexe 50b7f491cc4582a9479aab1a8d3c3331e40c0cb17b99193840d87746f23199a3Virustotal results 68.12% 
2025-03-08n/aexe c5b5c385184b5c2d7ed666beb38bb10b703097573f7a6b42b7fdef78acf99c96n/aAmadey
2025-03-07n/aexe 9b45e0e9091f0647a315676409a3a05303067d475f2fa4096aeff1819844dce2n/aLummaStealer
2025-03-06n/aexe 1e6929de62071a495e46a9d1afcdf6ec1486867a220457aacfdfa5a6b6ff5df4Virustotal results 39.44% 
2025-03-05n/aexe b8e02f2bc0ffb42e8cf28e37a26d8d825f639079bf6d948f8debab6440ee5630Virustotal results 70.83%LummaStealer