URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.32/files/5254702106/LXkGFUT.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3587582
URL: http://176.46.157.32/files/5254702106/LXkGFUT.exe
URL Status:Offline
Host: 176.46.157.32
Date added:2025-07-21 16:07:10 UTC
Last online:2025-07-23 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-07-21 16:08:17 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:1 day, 19 hours, 26 minutes Poor (down since 2025-07-23 11:34:24 UTC)
Tags:c2-monitor-auto dropped-by-amadey Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-23LXkGFUT.exeexe b7d90d510a979731bb407f980014f38c2f8a269acdb8f78bc6b0ed80a8fdb2bbVirustotal results 30.56% Stealc
2025-07-23LXkGFUT.exeexe 9c8db22736769f388c36b03bc8cbb20b44c734666add20eb34b00253b756a0b0n/aStealc
2025-07-22LXkGFUT.exeexe b2c3c6e352faa8e7357f6da60e03a4d94421b33802c84445a8c72c8b7cd6b378Virustotal results 56.94%Stealc
2025-07-21LXkGFUT.exeexe af6acbd5ab0b2031d86503f7d94d191a16f7defafaf0ef1d033b363a7e6b8944Virustotal results 43.06%Stealc
2025-07-21LXkGFUT.exeexe ea56ae1babc9f9c7b7c94c34edf38e293f210735ee57fb7a0ff1e5ecdedf8f36Virustotal results 49.30%Stealc