URLhaus Database

You are currently viewing the URLhaus database entry for http://176.113.115.7/files/6142491850/s7MG2VL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3476643
URL: http://176.113.115.7/files/6142491850/s7MG2VL.exe
URL Status:Offline
Host: 176.113.115.7
Date added:2025-03-14 09:30:18 UTC
Last online:2025-03-21 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: TornadoAV_dev
Abuse complaint sent (?): Yes (2025-03-14 09:31:09 UTC to abuse{at}starcrecium[dot]com)
Takedown time:6 days, 19 hours, 59 minutes Bad (down since 2025-03-21 05:30:19 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-20n/aexe 7562bf14f527dab8c0e897e693af05b834b85afc5e45f2f102ce600c7c0ea241Virustotal results 56.16% 
2025-03-19n/aexe 0b691b4d330f0513dee0080030b79cd916e51eb7d854839fe5a78247b700c45dn/aLummaStealer
2025-03-17n/aexe b8a764c238ba1bb151ee919f88b43e0c401d049faa607196b7cfcfd527cf85d8Virustotal results 61.11%LummaStealer
2025-03-16n/aexe 9ebca4a7a9e6f565aa9a2aff7ef938872837933d7c7b3d974026a8c09318151dn/a 
2025-03-14n/aexe f311de293f2e7fb8487bfc25da196a92c2060cb3bb41117928b80ffde70c196fVirustotal results 67.12%LummaStealer