URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.152.46/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3590323
URL: http://176.46.152.46/2.exe
URL Status:Offline
Host: 176.46.152.46
Date added:2025-07-26 10:02:09 UTC
Last online:2025-11-12 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-26 10:03:11 UTC to abuse{at}as214351[dot]com)
Takedown time:3 months, 19 days, 0 hours, 19 minutes Bad (down since 2025-11-12 10:22:50 UTC)
Tags:Amadey exe LummaStealer Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-302.exeexe 00ccb3b5a2a11689366587a20c3a1cee0e65414f04ed13b5e70c7e1376c748d0Virustotal results 58.57% Rhadamanthys
2025-10-162.exeexe a97963995a77a30452ae1c003eb77dbc02bc5bd65de16d31416d3d874de5482bVirustotal results 40.28% Amadey
2025-10-152.exeexe 5e39f5bde1dbba4d1c2a3541e1ebf3dc44a89d1980d98fb4f7b0ab023744c1efn/a
2025-09-072.exeexe 0550c78069d778acf2fe32c87b5898e90de62f08a6b741aefd332e64e68e8c76Virustotal results 47.22%LummaStealer
2025-09-012.exeexe 80d22f36c433957648a341d57db6e5f0661d5d08079e5bea559a9c9ebc516e17n/aLummaStealer
2025-08-092.exeexe 6c64ca65b8429969526c79fe0bb574b2f96375497e29ee33860991c08dc4c992n/aXTinyLoader
2025-07-312.exeexe ed86fd8c901282c02a5075911f24cbb2983a907cd0e5068cc3ae6d3ed2f78d9bVirustotal results 58.33%XTinyLoader
2025-07-262.exeexe c1d781f4c9469977a32f2ad6edea4fda98e6a8eda5aa10149be2311cb369c48aVirustotal results 52.78%XTinyLoader