URLhaus Database

You are currently viewing the URLhaus database entry for http://dfgjhkllkhuuk.info/load/ojujn.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3866177
URL: http://dfgjhkllkhuuk.info/load/ojujn.exe
URL Status:Offline
Host: dfgjhkllkhuuk.info
Date added:2026-06-17 08:04:10 UTC
Last online:2026-06-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-06-17 08:05:17 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 days, 8 hours, 11 minutes Bad (down since 2026-06-22 16:16:26 UTC)
Tags:exe LummaStealer opendir RemusStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-22ojujn.exeexe e747889fd668f0afe42f439e10fb16b8ed8dae4f5321fdda368965a1d5cc3d6fn/a RemusStealer
2026-06-21ojujn.exeexe f32eb9c6f0e600d49750ce96e64991dab7424aa92332fe92520569869a3d1c59n/a RemusStealer
2026-06-20ojujn.exeexe 374b7151463dffec6f7ae9a5ab73760e53a99b5cd29ffbb8b90936f33440e9f0n/a RemusStealer
2026-06-20ojujn.exeexe 61269eca1d774d5e3bc5fb9445de05bb7b0f9057876a9ef7779ecd5ca1582accn/a RemusStealer
2026-06-19ojujn.exeexe b9b7602e0b929dd2bae9e87b53d5ab1e0a236fe466ea4628c3b8fc32cc2ed899n/a LummaStealer
2026-06-19ojujn.exeexe 9817c80e1108f291efd2eb04a7b5abc8ca5895788b8a3934d1c3dded97d4b124n/a LummaStealer
2026-06-18ojujn.exeexe 47b98c99d290618540083c6de80ffe770425eca86892ce5a450a422d6a560c0bn/a
2026-06-17ojujn.exeexe a9cd794d41cf7f9e7a10f5b2baa014b3c626a660f876d08a7a64bbf9350b639an/a