URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/7908530566/zDP7Tw4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3558141
URL: http://185.156.72.2/files/7908530566/zDP7Tw4.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-06-04 12:40:07 UTC
Last online:2025-06-05 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-06-04 12:41:07 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:1 day, 4 hours, 22 minutes Poor (down since 2025-06-05 17:04:03 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-05zDP7Tw4.exeexe 46fd49728c6fdfbe4b67007a956558db9822e8bf25117cad65d631b301360b1cVirustotal results 25.35%LummaStealer
2025-06-04zDP7Tw4.exeexe e4879877a8f18a7fe1e814755edc0a039f62517df4dbd076ea4343042000742dVirustotal results 37.50%LummaStealer