URLhaus Database

You are currently viewing the URLhaus database entry for http://45.140.146.180/44273.4360444444.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1075053
URL: http://45.140.146.180/44273.4360444444.dat
URL Status:Offline
Host: 45.140.146.180
Date added:2021-03-18 11:09:15 UTC
Last online:2021-03-18 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: ffforward
Abuse complaint sent (?): Yes (2021-03-18 11:27:02 UTC to abuse{at}pq[dot]hosting)
Takedown time:1 hour, 6 minutes Good (down since 2021-03-18 12:33:39 UTC)
Tags:dll IcedID link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-1844273.4360444444.datdll 6e4646f6279944796256e61b808707e89f85c9b42f294178fe0f281e266f5caen/a IcedID
2021-03-1844273.4360444444.datdll 30a18fcbc45e5500120cae605fe0f05c4f9885268a956d8012978425e2b0e4can/a IcedID
2021-03-1844273.4360444444.datdll d4ac35225663a68edec834bfd5ea346d8559afe6322f740d93665481896fa150n/a IcedID
2021-03-1844273.4360444444.datdll e815b530617bbc559b2e3d6ba3259c5390410260584b8a94c1b805900a4d5cefn/aIcedID
2021-03-1844273.4360444444.datdll ff4eb79fbaf4de2356b179959279c3d5af1b19de5c44ea0d211ac9e4499061ecn/a IcedID