URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.32/files/6893304155/haHVBay.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3581080
URL: http://176.46.157.32/files/6893304155/haHVBay.exe
URL Status:Offline
Host: 176.46.157.32
Date added:2025-07-11 06:36:22 UTC
Last online:2025-07-16 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-07-11 06:37:20 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:5 days, 17 hours, 14 minutes Bad (down since 2025-07-16 23:51:35 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-14haHVBay.exeexe 27ea0fa21d8a6ad59ffc0d8a3aab51c32b4c5728aa1a69f6363bf42a2a13054fVirustotal results 50.00% 
2025-07-12haHVBay.exeexe 2ea63a3a86c328be1b8d2bb427e4059afaf9d97ef2bdc76cff7cc0c2c281b928Virustotal results 50.00%LummaStealer
2025-07-11haHVBay.exeexe 19abda2c15808af824f438774b5bb92556b9048b68a112f040dfb0787344f369Virustotal results 52.78%LummaStealer