URLhaus Database

You are currently viewing the URLhaus database entry for https://undo.sg/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3524345
URL: https://undo.sg/file.exe
URL Status:Offline
Host: undo.sg
Date added:2025-04-25 05:24:07 UTC
Last online:2025-05-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Malware domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2025-04-25 05:25:14 UTC to abuse{at}h2[dot]nexus)
Takedown time:16 days, 2 hours, 23 minutes Bad (down since 2025-05-11 07:48:43 UTC)
Tags:Lumma lummac LummaStealer stealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-10file.exeexe 0a768effcf174378939d3b7adfd661985183bb7fcd031cfc086d4394b3d2dc26n/a 
2025-05-09file.exeexe f3798c19503ebd51260bd80411fc1beaf2893626bd48a49ceab8b70734c48726n/aLummaStealer
2025-05-02file.exeexe c8899982d57caf6a16c95166ac167d0eb1b801fa238f4237c240b5935649b22an/a LummaStealer
2025-04-29file.exeexe be6e14517a4bac3e6bd3682d01e9139fcf51cd702770109a7d144f76c1a7ff6an/aLummaStealer
2025-04-28file.exeexe 385bd30e44dd85927d751b6c2b3a85a598f8ab27724f2a79d43b59bbdd94eff3Virustotal results 50.00%LummaStealer
2025-04-26file.exeexe 714e9be09c6a9a397a88e8b2cee5fed08ad5c4cec1de41789d68fd2886d77c2fn/a 
2025-04-25file.exeexe 8dbab5db9d1c394a9a46efd3d7619dcebcdb2131edef1f2db9f6d11d6df48f1bVirustotal results 47.22%LummaStealer