URLhaus Database

You are currently viewing the URLhaus database entry for http://ejeana.co.ug/m1/ctf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2199420
URL: http://ejeana.co.ug/m1/ctf.exe
URL Status:Offline
Host: ejeana.co.ug
Date added:2022-05-17 15:30:15 UTC
Last online:2022-05-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-05-21 12:00:08 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:3 days, 23 hours, 19 minutes Bad (down since 2022-05-21 14:50:32 UTC)
Tags:dofoil link exe Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-19n/aexe 42e762edf81721311214367b6a6f76eb5abdab347f3919c34bf1a2436544c409n/a 
2022-05-18n/aexe 3e81f3497be93eb5332e0635a74a360c07871c7f3c48806ad82659533f3d2f5dn/aSmoke Loader
2022-05-18n/aexe 73ff374c87dca3383cff39f9bcb242cb00130d83daed745461245a8c52185046Virustotal results 35.29%Smoke Loader
2022-05-18n/aexe 3675d239f3a7fe82634e98680149821d4e573e349f183b0aec58261450d4807cn/aSmoke Loader
2022-05-18n/aexe d999ea24a63d51de747956882700b282102765b563c8b477a038e3ec17a31679n/aSmoke Loader
2022-05-18n/aexe 689a7f0c1d9b07e89dbee1fd8c5692e1475b5b60ecb5e7d633c56bde9cb7fbc2n/a Smoke Loader
2022-05-17n/aexe 1fd5bb4099b8a39092316f76c24b18a0e72535969170e2a1f57f0168e6b6ab0fn/a Smoke Loader
2022-05-17n/aexe 07639f53abc1cfab5e592ce39d3b9d52ad7d64dc1505a50b864f242310f43c3eVirustotal results 34.78%Smoke Loader
2022-05-17n/aexe a116b9c9f5c2fc29c203e304c678ce6fbd08f0710e15c474c9b127201a26a94cn/aSmoke Loader