URLhaus Database

You are currently viewing the URLhaus database entry for http://80.64.18.161/luma/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3538343
URL: http://80.64.18.161/luma/random.exe
URL Status:Offline
Host: 80.64.18.161
Date added:2025-05-08 05:10:11 UTC
Last online:2025-05-13 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-08 05:11:07 UTC to abuse{at}stimllc[dot]ru)
Takedown time:5 days, 9 hours, 1 minutes Bad (down since 2025-05-13 14:12:18 UTC)
Tags:LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-10random.exeexe 46001edba07e9a540d8b14c660e83eac28a5da86aac610d40f2413a67fd8c766Virustotal results 70.83% 
2025-05-09random.exeexe 18161b498e4183808a2faf0730bcb842157b120dc7fd5e4971f201979a1b58cbn/a
2025-05-09random.exeexe c9890997e693ecb7c7f3dc2c2db0ca5696eeec5f52778d95e0f4c097d23644e9n/aLummaStealer
2025-05-09random.exeexe 75114b340583d9a9045380bd135307ac39148fb45b047f454de7c495cb67c561n/aLummaStealer
2025-05-08random.exeexe 7122ecabf6fd78829ff5dd54133213a6e91a4ea5564219b48acc9af7adf749c8n/aLummaStealer
2025-05-08random.exeexe 91025edf9aadd62073a422159a6c81b213cebed95b31fd86b70984a607bb108cn/aLummaStealer
2025-05-08random.exeexe b10e0e48bf3a23352b0fec032de8160a902680c73e49ff6fd4ebceb857b34916n/aLummaStealer
2025-05-08random.exeexe eba7e507e00f71e75207c5e18c2a6feda50452686520a888f00742dcf574450bn/aLummaStealer
2025-05-08random.exeexe 9b416d495be3632084094ef0c50ef47009a1d63256859023038436c5bb3e5a99n/aLummaStealer
2025-05-08random.exeexe 8232a11066fe5a6f552302da37f9b4e42f313bbeaf51f86c61fbf84bd95b1ca9n/aLummaStealer
2025-05-08random.exeexe f5cd5f7913631bc9c5691cf4219c43799623025bdbceac5e6fa8277cea6dfa56n/aLummaStealer
2025-05-08random.exeexe 820e40285429a78a439c4f2fd7b89e463adc156be8617bf49cf7712b698d2e41Virustotal results 61.11%LummaStealer
2025-05-08random.exeexe 9f7fd12613de50dc9bd9416cf2580dadc1baa699277e056149853fcebc012672n/aLummaStealer