URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.60/inc/alex12312.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3585449
URL: http://176.46.157.60/inc/alex12312.exe
URL Status:Offline
Host: 176.46.157.60
Date added:2025-07-18 10:12:13 UTC
Last online:2025-07-22 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-07-18 10:13:15 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:3 days, 14 hours, 18 minutes Bad (down since 2025-07-22 00:32:09 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-20alex12312.exeexe e9114b6b2eeb4a83d172831a84668b7851176d87a6ed6053ae2261cb7f448e95Virustotal results 51.39%LummaStealer
2025-07-18alex12312.exeexe bc7bf26711d0bad8a51f903f75b59015a3c7d0662f1f096b0d4775af3d2bd965Virustotal results 58.57%LummaStealer
2025-07-18alex12312.exeexe d773b18221c55ad3725609be461aaf280a6f79b3ef325d2d5fd50d9adba78968Virustotal results 48.61%LummaStealer