URLhaus Database

You are currently viewing the URLhaus database entry for https://nordic-food.ro/systems/tmp/ChromeSetup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2528449
URL: https://nordic-food.ro/systems/tmp/ChromeSetup.exe
URL Status:Offline
Host: nordic-food.ro
Date added:2023-02-03 01:49:10 UTC
Last online:2023-02-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-02-03 01:50:08 UTC to abuse-lir{at}mediasat[dot]ro)
Takedown time:16 hours, 40 minutes Good (down since 2023-02-03 18:30:23 UTC)
Tags:32 exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-03n/aexe 31461459b39e9ae563ba52d2fe2bcf6d9ba70b9cefc6a2da410673960c5558efn/a Smoke Loader
2023-02-03n/aexe 30c06bafae44cd57f824a3c46aa9e0422e03d0c768b5c3b677b1fffb3eb39c57n/aRedLineStealer
2023-02-03n/aexe be943cff3ddc8fddaba89b354a54c6097cc4182be24253bf5edfd06565ad5f90Virustotal results 33.33%Smoke Loader
2023-02-03n/aexe cdc05a9a57bc6d5c7232d415f9c68bdc6d7ce709a0efbe8c9753300273ee955dVirustotal results 37.68% Smoke Loader
2023-02-03n/aexe 88354b37427492c5730a4d0d8576c612ae355dcbddc8e3260e1aa5e5f429909cVirustotal results 33.33%Smoke Loader
2023-02-03n/aexe 158004c34b25ef3e94f1664151012731bcb029a905205f16c42c4f3087f129eeVirustotal results 32.86%Smoke Loader
2023-02-03n/aexe 2735371bbffec3c5d97b7b5f060485920a152a70629215cba0d66c91142009f0n/aSmoke Loader
2023-02-03n/aexe 90988c815a0d7bca3e0e8cc3ebde74d55e3eda874687ed7b92bb3528c2745d57n/aSmoke Loader
2023-02-03n/aexe 084c0aa92e9a0cc7c14f9bf1215cc72f56aabb22d8ec7283abf77d4be03c7c98n/aSmoke Loader
2023-02-03n/aexe 323d285f670c92118fa148f0511a13c2d3fb12806a3c50e050946590ebc19881n/aSmoke Loader
2023-02-03n/aexe 9ce9dffd37ec53a9834ca8176c8c8515cb6882fda39afa9dc748f427541b7922Virustotal results 34.29%Smoke Loader
2023-02-03n/aexe 9769412727355afacbe12462bf964f8f1f509ef80ed52783f1fbad5b3cfb8983Virustotal results 35.71%Smoke Loader
2023-02-03n/aexe d88d2826c07358bf80c09379121d77e21077f7261a6ac7bb3daaea95e7692cb8Virustotal results 35.29%Smoke Loader