URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/6336929412/Q1yLGzl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3542098
URL: http://185.156.72.2/files/6336929412/Q1yLGzl.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-05-12 14:28:12 UTC
Last online:2025-07-02 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-12 14:29:08 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:1 month, 20 days, 22 hours, 9 minutes Bad (down since 2025-07-02 12:38:39 UTC)
Tags:exe LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-21Q1yLGzl.exeexe bdfb1adb14883e192822dd055819e5841f92252ada0a9b6efb5318f4c1ab8b6fVirustotal results 15.28%LummaStealer
2025-05-20Q1yLGzl.exeexe be97ee8891059eca18466b11b7d889caafdb88065ce2e1a25518de6b9872e15an/a LummaStealer
2025-05-20Q1yLGzl.exeexe 4868d0e96360540acb078226a455c5b45ba0ed8d45e8566d41ceec56e7046841n/aLummaStealer
2025-05-18Q1yLGzl.exeexe 60d777218b109112f8a847085773a474a794a4ff1b92495cad36f75fe1165984n/a 
2025-05-13Q1yLGzl.exeexe c7903d94acc6d003135a00580ec939b4a1d00cd29134c5102e2fdc2721ee9072n/aLummaStealer
2025-05-12Q1yLGzl.exeexe fafe229608a69f487c376eeaaacd6f9be57486d6d84b81829b6fd0ed0aeb1d36Virustotal results 62.50%LummaStealer