URLhaus Database

You are currently viewing the URLhaus database entry for http://formula-smaku.com/log/star.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1874086
URL: http://formula-smaku.com/log/star.exe
URL Status:Offline
Host: formula-smaku.com
Date added:2021-12-11 01:22:05 UTC
Last online:2021-12-14 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-11 01:24:08 UTC to abuse{at}hostprolab[dot]com[dot]ua)
Takedown time:2 days, 23 hours, 52 minutes Poor (down since 2021-12-14 01:16:51 UTC)
Tags:32 exe Globeimposter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-12n/aexe ea48aea18095fe3d2e7497cd5a9d1120cada3124422b1f2527d2cf0b1735d8a9n/a 
2021-12-11n/aexe 36035b1a4995acb201c2b2160000d4477a31a2222c3f6bdc25a32d53d930bcfdn/aRansomware.GlobeImposter
2021-12-11n/aexe 7041d52bfdf9f013e73c2bb27112d79a7f0863f72cd624011658bc09defe6665n/a
2021-12-11n/aexe 9024ff20ea76db96bcc17fa546ee3c0fa0194b500975bb1c527ea679e7eef632Virustotal results 77.94% Ransomware.GlobeImposter
2021-12-11n/aexe 8e7ecf925a4e328f88f41cfa929c6ecd512117f446d5cdaf327a9c026758d689n/a Ransomware.GlobeImposter
2021-12-11n/aexe 38df9f7ee6504ebae134f8f446caaa0cf9f7c2c258f51023bc7eddd68e5aad12Virustotal results 36.76%Ransomware.GlobeImposter