URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.32/files/7453936223/RenT7Wg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3579353
URL: http://176.46.157.32/files/7453936223/RenT7Wg.exe
URL Status:Offline
Host: 176.46.157.32
Date added:2025-07-09 05:52:08 UTC
Last online:2025-07-23 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-07-09 05:53:15 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:14 days, 5 hours, 13 minutes Bad (down since 2025-07-23 11:06:28 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-22RenT7Wg.exeexe f65c4597b4d6253d0f5c566e9dc2e14d6f21538136ee05050e7284b28c6f5e43Virustotal results 44.44%LummaStealer
2025-07-20RenT7Wg.exeexe 8d70c9ac311806afbe9a3bf61310a3d7df290ca5a22b401ab50d5b4465562c6fVirustotal results 50.00% 
2025-07-17RenT7Wg.exeexe dc7221ade793244e3eadb42fb48886348663c71a58c5b252600b60df521e188fVirustotal results 51.39% 
2025-07-13RenT7Wg.exeexe 5696c9750d436a7059f40fb6f54e3dd7a91ba8c985c00636cd5a23f2f798fc28Virustotal results 44.44% 
2025-07-09RenT7Wg.exeexe 7dc2890b0c7b364430d4828cb209813dd0656e46d94f28a4cce39f46359f927fVirustotal results 63.89%LummaStealer