URLhaus Database

You are currently viewing the URLhaus database entry for http://80.64.18.219/files/unique1/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3532657
URL: http://80.64.18.219/files/unique1/random.exe
URL Status:Offline
Host: 80.64.18.219
Date added:2025-05-02 11:59:22 UTC
Last online:2025-05-07 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-02 12:00:10 UTC to abuse{at}stimllc[dot]ru)
Takedown time:5 days, 1 hours, 30 minutes Bad (down since 2025-05-07 13:31:06 UTC)
Tags:LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-05random.exeexe 8306c7ed522d0e92cf3d4696f84de1ad7dffc0c9044bab522d7e8c6579a0203fn/a Vidar
2025-05-02random.exeexe 650a60de9e5e1c4a98029e6ac305d17b03349b354a7570409419340b41732d3aVirustotal results 16.90%LummaStealer
2025-05-02random.exeexe 35d825988b4411c29dbf9360578872c722c58d63c8ae1967153c9a28dfe45375Virustotal results 46.48%LummaStealer