URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.158.8/files/5254702106/LXkGFUT.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3590305
URL: http://176.46.158.8/files/5254702106/LXkGFUT.exe
URL Status:Offline
Host: 176.46.158.8
Date added:2025-07-26 09:43:14 UTC
Last online:2025-08-14 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-26 09:44:13 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:18 days, 23 hours, 0 minutes Bad (down since 2025-08-14 08:45:05 UTC)
Tags:exe Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-01LXkGFUT.exeexe 12b78f63fd3358c9cf5184a6a4af662cc7e9e8706a25c864e42382756418655fn/a Stealc
2025-07-30LXkGFUT.exeexe d5d41e2838bb96f961eb967b3cb7098f81d1d8b7090e1a0ac083b64d485ff0d9n/a Stealc
2025-07-27LXkGFUT.exeexe f922f454f51b972cee4a6404d9fa84537d9f73d49e8fbf3565108acd21ba881dVirustotal results 41.67% Stealc
2025-07-26LXkGFUT.exeexe b35914d9b4b2368cfa80c0f8db722540a4894f73f00a2cb8978402bac731f3a6Virustotal results 45.07%Stealc
2025-07-26LXkGFUT.exeexe 5c1926638a27441d16757c927f6795364468fa7c8fb3e18b35a0d3972caae24eVirustotal results 51.39%Stealc