URLhaus Database

You are currently viewing the URLhaus database entry for http://172.93.193.37/amd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2498617
URL: http://172.93.193.37/amd.exe
URL Status:Offline
Host: 172.93.193.37
Date added:2023-01-06 07:44:12 UTC
Last online:2023-01-06 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-06 07:45:08 UTC to abuse-reports{at}cloudzy[dot]com)
Takedown time:5 hours, 19 minutes Good (down since 2023-01-06 13:04:49 UTC)
Tags:DanaBot link exe Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-06n/aexe 428c1c48e636421a85235a35b5228472e5441ca9b60eb9bd776a182fbaa9f1b7n/aSmoke Loader
2023-01-06n/aexe a8e8ac7c8c5e8260b41895070f809f4e817c936ad6877dbacf6f7f963abba250n/aDanaBot
2023-01-06n/aexe 991784842d251cd682b56f4639e49ffd77bd1fa272caa8734a6ae78647daa761Virustotal results 47.89%Smoke Loader
2023-01-06n/aexe 11bce2743ff66806ca0098b8237009f9ee04a79fc7351b93735051ce3cca880en/aSmoke Loader