URLhaus Database

You are currently viewing the URLhaus database entry for http://77.73.131.123/files/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2275071
URL: http://77.73.131.123/files/1.exe
URL Status:Offline
Host: 77.73.131.123
Date added:2022-08-20 14:23:04 UTC
Last online:2022-08-22 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-20 14:24:04 UTC to abuse{at}aeza[dot]net)
Takedown time:1 day, 12 hours, 30 minutes Poor (down since 2022-08-22 02:54:17 UTC)
Tags:exe opendir RecordBreaker link RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-22n/aexe 7f6cfa405d87c5434488f95acfc65c5db6fe108280cbed61bbfa4d851b0ad0a0n/a RecordBreaker
2022-08-21n/aexe 4d8ed3b5c886f88d1fcc212d1effb0c6da464ace6110c1f66515c7a06e4836e6n/a RecordBreaker
2022-08-21n/aexe f718fc06b1300b9dd83e6e24e7ee9f4db6c4b8b0f8d43bd0cd0901a40cc570d8n/a RecordBreaker
2022-08-21n/aexe a3703cecdb1bf5e9dce319edca331fa189e3d5605b72463688cad3cbc8b448f6n/a RecordBreaker
2022-08-21n/aexe b30d53e35b1968a9cd95570009f933255c4a6fe04e789ae78f1eac547e5c4635n/a RecordBreaker
2022-08-21n/aexe 4c6fa6df5268f281cf0c959a851caf9e1feb55b8ebecd3503a1eccc8854a2e02n/a Smoke Loader
2022-08-21n/aexe e68eb5c847f58f8a3322208932734601f1c8909f529e5d64aec129e095f02ad3n/aRedLineStealer
2022-08-21n/aexe 5222e70ffdce094f5e5127de0745c5bc85cba49475fd5fc0d5065410aa0847a0n/a RecordBreaker
2022-08-21n/aexe 8c3228542fd34787f800492e521752067b5dd1e5ecbf8f3181d23e3e600941f9n/a RedLineStealer
2022-08-21n/aexe e4f934307f80e86525df56d4a8d83bb9aac6879f1a0d3b2fe96009f5e672a901n/a Smoke Loader
2022-08-21n/aexe f1f713eed337b5689345785e07be5d7136f34c0195efdee8ac2230144c57e604n/aRedLineStealer
2022-08-21n/aexe 184c1955fd7c0fa521c7e30991e5b5ce27ad6833621782baa61900448f2eabean/aRedLineStealer
2022-08-21n/aexe 520b90f9db13559947f918a5a3e76de5a7aa0ec94b3c20b86ad156eb00b37c24n/a 
2022-08-21n/aexe 08235bdc71cd94758e9dd5231c3dd2237a12c025a7ff0dc4571927bf95eb88acn/a 
2022-08-21n/aexe 84edea62538f3dffb999ace09bfd7a276ade6b32ba4c4ec35fdd28f4ae939ba1n/aSmoke Loader
2022-08-21n/aexe aa7a3eebc62733bd966cb5d87b276d66d6079b9327f8f34a4dd4926e11be284en/a 
2022-08-20n/aexe 36421ce023834e9846b49a73a152b60c2525c45ef971cdc98647facd90236873n/a 
2022-08-20n/aexe 2485c3f6db364adc2a70b75245640656ee89ad34c72f1c0dc695566e0986c939n/aSmoke Loader
2022-08-20n/aexe 482fddee1ce10a989939e095face8f44aed814198711c5b1a90c49617a464698n/a 
2022-08-20n/aexe 336272ca785b39afae6b6e5a1f90ee3afb54779dfc4f6ffe682c26273d722011n/a 
2022-08-20n/aexe ccfa2a67d01921867191fc088fd2e3c5c60209b1e6423e1586218d739f47a145Virustotal results 45.71%Smoke Loader
2022-08-20n/aexe dfdfce3dac6eac8d2533b51a7ea77eb716b9bde2f270f58387b976948caaa5d0n/a RedLineStealer
2022-08-20n/aexe 0d5f72de2638164abf4e3c913cc91721e5c011fb85f7ccb81c86f8d17712b2d6n/aSmoke Loader