URLhaus Database

You are currently viewing the URLhaus database entry for http://77.73.131.83/cdn/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2274170
URL: http://77.73.131.83/cdn/1.exe
URL Status:Offline
Host: 77.73.131.83
Date added:2022-08-18 06:22:04 UTC
Last online:2022-08-18 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-18 06:23:04 UTC to abuse{at}aeza[dot]net)
Takedown time:2 hours, 58 minutes Good (down since 2022-08-18 09:21:33 UTC)
Tags:exe opendir RecordBreaker link RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-18n/aexe 5a152b641f026ba07fb366ef54c795f16a8a095683233d6ae56e8780d8d71ccdn/a Smoke Loader
2022-08-18n/aexe efb1f86744193b39bc3a85e3c6009036757e1736c6d4b764025723f783968617Virustotal results 42.25% RedLineStealer
2022-08-18n/aexe 538dcfdf83192a091a5b38d65a397deed5f90b7438089c95c3976b6e08725b53Virustotal results 42.86%RecordBreaker
2022-08-18n/aexe 8e09063d09dedc36e06a586818d6d2ce9d94dc7ab3f388cf1f7379d9ad7ba76fVirustotal results 33.80% Smoke Loader
2022-08-18n/aexe bab1360b32a15d819fecaa045b25852f4002fb6bc0a5c12d1356666053387fcan/aRedLineStealer