URLhaus Database

You are currently viewing the URLhaus database entry for http://45.141.233.196/files/5254702106/LXkGFUT.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3594016
URL: http://45.141.233.196/files/5254702106/LXkGFUT.exe
URL Status:Offline
Host: 45.141.233.196
Date added:2025-08-01 06:14:11 UTC
Last online:2025-08-04 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-08-01 06:15:19 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 days, 5 hours, 40 minutes Bad (down since 2025-08-04 11:55:31 UTC)
Tags:c2-monitor-auto dropped-by-amadey Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-03LXkGFUT.exeexe 1ff9694c0c8b60ff6bef904d9f002b7ce4a27563be57b550a6acaca5f83f9dc3Virustotal results 43.06%Stealc
2025-08-01LXkGFUT.exeexe 6e76ac5121bb58809c217bc73cb461e85201b29b3c968c5d9e4dea2a9d38e405Virustotal results 27.78%Stealc
2025-08-01LXkGFUT.exeexe d5d41e2838bb96f961eb967b3cb7098f81d1d8b7090e1a0ac083b64d485ff0d9Virustotal results 62.50% Stealc