URLhaus Database

You are currently viewing the URLhaus database entry for http://8freeprivacytoolsforyou.xyz/downloads/toolspab2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1545009
URL: http://8freeprivacytoolsforyou.xyz/downloads/toolspab2.exe
URL Status:Offline
Host: 8freeprivacytoolsforyou.xyz
Date added:2021-08-19 06:29:04 UTC
Last online:2021-08-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-19 06:30:04 UTC to abuse{at}hostzealot[dot]com)
Takedown time:3 hours, 37 minutes Good (down since 2021-08-19 10:07:55 UTC)
Tags:exe RaccoonStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-19n/aexe 92e576963128d956b98f423af33a3a2395e6a16f7d44855cfc2fff71c0651329n/aSmoke Loader
2021-08-19n/aexe 5152274dbe1cc44da156f29d1ff2858e583237bdc24ced137265cd3668ba851eVirustotal results 27.27%Smoke Loader
2021-08-19n/aexe 608248c1ef7bab54f8a7aeffaf618187a6f20d3bc829a6c6de625e2a2a376f2bn/aSmoke Loader
2021-08-19n/aexe 5fc5ab3f922510924c13f1018ba4d5d94f990f3885da41d68a38603020cf9b27n/a1xxbot
2021-08-19n/aexe a19317b14abc6d4c1294aaaeab29d0ada023dffa37025c839671c193a74fd519Virustotal results 31.25%Smoke Loader
2021-08-19n/aexe 11d175a08e1f4fc351af4e4c2c0549168d4c235a497f3bc1f278e8cb46b972e1Virustotal results 29.41%RaccoonStealer