URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/6691015685/fPbjy1Q.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3547829
URL: http://185.156.72.2/files/6691015685/fPbjy1Q.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-05-20 06:57:07 UTC
Last online:2025-05-26 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-20 06:58:07 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:6 days, 16 hours, 50 minutes Bad (down since 2025-05-26 23:48:55 UTC)
Tags:LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-24fPbjy1Q.exeexe b8739b2e9b6dc483729d2ce2074b4b3376013e7c881d446f040a59057357d9bdn/aLummaStealer
2025-05-24fPbjy1Q.exeexe 0b834dde3302ab539bb6a9c6bc8830b182a69e8181f2f14fcd76913ab1adaf93n/aStealc
2025-05-22fPbjy1Q.exeexe cc0593c1a8fa13639aaaaea7b525bd071edb956306b3da3bcbc01454c20fee92n/aLummaStealer
2025-05-21fPbjy1Q.exeexe 36adb8e451b85b56ba6ddaed008496f245f88f782c593480d17567530213958bVirustotal results 34.72%LummaStealer
2025-05-20fPbjy1Q.exeexe 1831978a8f7b06b6b432d18c82142d54570db22a59cd7bc43915332d72c5d8c5Virustotal results 31.94%Stealc
2025-05-20fPbjy1Q.exeexe 2d68e55615aa746dadfdcd59af924580973d68c89ccfb0317b9fc6579470f41fVirustotal results 41.67% LummaStealer
2025-05-20fPbjy1Q.exeexe 33599b1eda6bd58205fb0dca45dd5c772aadb7e34bc150ca4152d3ab07c127b4Virustotal results 40.28% LummaStealer