URLhaus Database

You are currently viewing the URLhaus database entry for http://77.90.153.244/v7942.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3478380
URL: http://77.90.153.244/v7942.exe
URL Status:Offline
Host: 77.90.153.244
Date added:2025-03-15 14:01:25 UTC
Last online:2025-04-14 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-03-15 14:02:06 UTC to abuse{at}virtualine[dot]org)
Takedown time:29 days, 19 hours, 58 minutes Bad (down since 2025-04-14 10:00:48 UTC)
Tags:LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-05v7942.exeexe f6fbc80ec9718b3ad7fe6f0de73aedf067d1d43a283f677b58ae9f5d283560can/aVidar
2025-04-03v7942.exeexe 6736fc5910c521c3b94093d44f0b8774b32c579a354fd2d850bd686766b0b696n/aVidar
2025-04-02v7942.exeexe a9180506bccc383d2fbd08b71cf8f24f36827bae1fae11fbb62e5c1dbf77cea6n/aLummaStealer
2025-03-30n/aexe e5186a04536313599bea259d6fefac44b168d81e08dcc36e54b2c6ff08374efdn/a 
2025-03-29n/aexe 3c5a551b8fee65ffc444a3c0730b990591c3a95e442426563539f0a2ca3871d2Virustotal results 28.77%LummaStealer
2025-03-25n/aexe 8e5021734b22342186a7b51235fbccc3d72ca27aa940c5b5c5e876d9fd406a85n/aVidar
2025-03-25n/aexe 8e5021734b22342186a7b51235fbccc3d72ca27aa940c5b5c5e876d9fd406a85n/aVidar
2025-03-22n/aexe 09d916ffc4140580a93ccba92d9d43c69675b8f118eafd24f6c1f251f129aa56n/a Vidar
2025-03-17n/aexe 52f108f00940080bcc8548cac70d0ee9d99f1f82381ae1b81eb9cfbc0449536an/aVidar
2025-03-15n/aexe 53d491fcb95b0cd2c073b1a2b7dc8c032e9de2d9422ac13170fe5975b78f6a7en/aVidar
2025-03-15n/aexe fe0d2c8f9e42e9672c51e3f1d478f9398fe88c6f31f83cadbb07d3bb064753c6Virustotal results 53.42%Vidar