URLhaus Database

You are currently viewing the URLhaus database entry for https://wetuspost.xyz/fixtool.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2117698
URL: https://wetuspost.xyz/fixtool.exe
URL Status:Offline
Host: wetuspost.xyz
Date added:2022-03-28 18:17:39 UTC
Last online:2022-03-29 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 18:18:32 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:11 hours, 53 minutes Good (down since 2022-03-29 06:12:25 UTC)
Tags:Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-29n/aexe 0b1351b2e38c303082e8a6fececf544be33c520509bcc34fe1779fb12d0b5a55n/a 
2022-03-29n/aexe d7e2e730c56f2778ec614fda4bf7d652a6a38687dc78c20ba3f1e11d3ff6607an/a 
2022-03-29n/aexe 561e48eb81c52058e4aa20d4265b655daf4c62064991959ed1f61436bc8179fdn/a 
2022-03-29n/aexe c5f1c753ac9e084143b58ce9867c6e7523664aea2f80d036ea69d46be43e00a9n/a 
2022-03-28n/aexe 2c363ade58bb13d5ee28c1b8a95c302cf9e3fe5345978ae356389de72f2c427en/a 
2022-03-28n/aexe 8665051e721ef48705045a1bd622508c43795f54c808165a6966fa1de25f6e22n/a
2022-03-28n/aexe dce897f9adc999bb2dd81e4d217af610a05bd161721c540528478a887e1a51afn/a 
2022-03-28n/aexe 9422fb5bd5d505b7b47c680c110a5487b5667c8885c714258432a8e14c3cb942n/a 
2022-03-28n/aexe dca84ac7fbc6543a8ff0d1bca89362221b2eb91a3004c6feda2f1a50a85d19d0n/aSmoke Loader