URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.120.8/pdfreader.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2275589
URL: http://172.245.120.8/pdfreader.exe
URL Status:Offline
Host: 172.245.120.8
Date added:2022-08-22 12:42:06 UTC
Last online:2022-09-09 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-22 12:43:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:17 days, 11 hours, 54 minutes Bad (down since 2022-09-09 00:37:51 UTC)
Tags:32 AveMariaRAT link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-25n/aexe 3549cc8f80003ee1a326ed6841dc12844ce696ea3566499d39fbab28d24bbf08n/aLoki
2022-08-23n/aexe 90205826eb40d5d4b454c2cfde44abe49f6c3b471681c700e30b45eb5078eee2Virustotal results 26.76% 
2022-08-22n/aexe 418b8dcfebca751193d5a07fd059507d01b5eba3418ca4843f4d9c1dacce0d90n/aLoki
2022-08-22n/aexe 479e9ffe2e1f53da21b1cd438c9b88e04a3f0d6f09f4a1c4a50d859a11940356Virustotal results 26.76%AveMariaRAT