URLhaus Database

You are currently viewing the URLhaus database entry for http://45.138.74.104/cdn/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2275335
URL: http://45.138.74.104/cdn/1.exe
URL Status:Offline
Host: 45.138.74.104
Date added:2022-08-21 14:53:02 UTC
Last online:2022-08-22 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-21 14:54:05 UTC to abuse{at}aeza[dot]net)
Takedown time:11 hours, 51 minutes Good (down since 2022-08-22 02:45:51 UTC)
Tags:exe opendir RecordBreaker link RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-22n/aexe 86ce330a6849fe8df5f261de69d27946ec3897aa70e08cd852bc622dd8011e69n/aSmoke Loader
2022-08-21n/aexe 8979bbae49633986969c5dd979128309c3b131b791f461b58912cfc7790c1317n/aRecordBreaker
2022-08-21n/aexe 515056cdf4a174cc6ac58615d36ff90f82d6f9827adc052b0d180d1e6e7394ecn/aRedLineStealer
2022-08-21n/aexe cc1d46313ecc439a58879808b21ad83d6819eebb7212e6b7b7ee63a504e8dcd6n/aRedLineStealer
2022-08-21n/aexe abd2a927ca79e5218a219f94cc0409b4bf5733ee8375e652d5ba369a441cb2bcn/aRedLineStealer
2022-08-21n/aexe 26613597e6d95832653eb761c6a7acc7275e54ac4f5b832442682085028ee8f0Virustotal results 30.00%Smoke Loader
2022-08-21n/aexe fcd96c4fd4bdd293263e4e3fe5447f170b2047fd7c483de1e0e639be61d1920aVirustotal results 30.00%Smoke Loader