URLhaus Database

You are currently viewing the URLhaus database entry for https://dupont-ingredient.ro/systems/ChromeSetup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2528858
URL: https://dupont-ingredient.ro/systems/ChromeSetup.exe
URL Status:Offline
Host: dupont-ingredient.ro
Date added:2023-02-03 10:13:09 UTC
Last online:2023-02-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-02-03 10:14:05 UTC to abuse-lir{at}mediasat[dot]ro)
Takedown time:8 hours, 11 minutes Good (down since 2023-02-03 18:25:38 UTC)
Tags:32 exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-03n/aexe e1e34a6202ecd40f6562b6daae9773b3b8a21626c1757b5d4f687767f13966fbn/a Smoke Loader
2023-02-03n/aexe 139eb0032a63f3e1e8bf067e18e998c1b59d3b66a4371c36a6bd1eed2b8ad718n/aSmoke Loader
2023-02-03n/aexe 9806a13cb503e12f44a04c6c6482f29d8fbc4f3f25d9027aeb5e3e9613c1100dn/a Smoke Loader
2023-02-03n/aexe 911f782875fadb4acced0ff282a43fdbe7b5769213d29c3454bf5e7f37019060Virustotal results 36.23%Smoke Loader
2023-02-03n/aexe 51a365bc6d01ef96c52a5ac2281374bd1d1c3a04757c3d038f665ffdbef178c3Virustotal results 33.33%RedLineStealer