URLhaus Database

You are currently viewing the URLhaus database entry for https://www.4sync.com/web/directDownload/yFKITjwD/4W5DbszB.eec54fd06d0698a4369a51e98735ffc1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3624369
URL: https://www.4sync.com/web/directDownload/yFKITjwD/4W5DbszB.eec54fd06d0698a4369a51e98735ffc1
URL Status:Offline
Host: www.4sync.com
Date added:2025-09-15 07:01:12 UTC
Last online:2025-09-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-09-15 07:02:12 UTC to abuse{at}webzilla[dot]com)
Takedown time:1 day, 2 hours, 45 minutes Poor (down since 2025-09-16 09:47:47 UTC)
Tags:dropped-by-amadey LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-16shoot.exeexe 520aeb92e5f5d14071da66bce45a94dd5fb9a600276f357c7f1fb192a95a7b62n/a LummaStealer
2025-09-15LummaC2.exeexe d27e2a587370c9c249cee01b81a2318f3ab65abef3766e329eeec25ff201fd0cVirustotal results 65.28% LummaStealer
2025-09-15LummaC2.exeexe 1169a84c14e419f4f103f2699ed46a464d4093d7a7e34d50db4bc7f819d2c48dVirustotal results 69.01%LummaStealer