URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/6629342726/rZBRvVk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3558811
URL: http://185.156.72.2/files/6629342726/rZBRvVk.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-06-07 06:51:05 UTC
Last online:2025-06-26 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-06-07 06:52:06 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:19 days, 3 hours, 8 minutes Bad (down since 2025-06-26 10:00:58 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-24rZBRvVk.exeexe d07d67267371fc989a38d3e125555cb8b4d34abbe526c7ef7f4229eea7cc8ac0n/aLummaStealer
2025-06-07rZBRvVk.exeexe 01cc769c6bd43f9ab133f406732ed8a730c6bbab80b8c42ee7b01fe3485d332eVirustotal results 63.89% LummaStealer
2025-06-07rZBRvVk.exeexe cca0be1f1b2f4254141c6ca8e13cf465ec351bf5e2f069826ff74285b8aad6acVirustotal results 15.28%