URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/5964586413/Bwwn8Qr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3556553
URL: http://185.156.72.2/files/5964586413/Bwwn8Qr.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-06-02 17:17:09 UTC
Last online:2025-06-03 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-06-02 17:18:08 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:19 hours, 55 minutes Good (down since 2025-06-03 13:13:13 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-03Bwwn8Qr.exeexe 7fcf9b9104318400d45489afd0e9a6c0beaa6ea81c0eab163e9ff4a257e2334dVirustotal results 37.50%LummaStealer
2025-06-02Bwwn8Qr.exeexe ce53c2e09c7e97fa17885e8e7e37a851897a31afda168598012c58d5f818cd91Virustotal results 26.39%LummaStealer
2025-06-02Bwwn8Qr.exeexe 39bd3ba338c11754cb8955e7ca6f4149068e4a1a029ade01e466bd01f450cee8Virustotal results 34.72%LummaStealer