URLhaus Database

You are currently viewing the URLhaus database entry for http://79.137.194.41/s.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2614048
URL: http://79.137.194.41/s.exe
URL Status:Offline
Host: 79.137.194.41
Date added:2023-04-19 16:04:10 UTC
Last online:2023-04-23 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-19 16:05:08 UTC to abuse{at}aeza[dot]net)
Takedown time:3 days, 12 hours, 54 minutes Bad (down since 2023-04-23 05:00:07 UTC)
Tags:exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-21n/aexe fc51e907d00e4bc82fda5bfec4b227e5ebf9c5ecce4acebaa24f17ecdfe5ebe8n/a Smoke Loader
2023-04-21n/aexe b0b79de26c03f281d9450dfb058032910a3e740ea2cf4063b1d7ae5414a40099n/a Smoke Loader
2023-04-21n/aexe d741cd6d1925c84baf07ea0c4a32cb5c7b6cdc2dd398962624c255dfb24b56bcn/a Smoke Loader
2023-04-21n/aexe 2d4cfb08c14422028ec4ca24a41ae0332b5782e839f845f566f68a62736d9d19Virustotal results 31.43%Smoke Loader
2023-04-20n/aexe 7884a345160e0ccdd4a9bda93b1905d540c0a697ab50d5df52da884fa145f783n/a Smoke Loader
2023-04-20n/aexe 042f6e8dc83d7909446de11c207066d4eb4af43fba4466c420290e1db8bafc6an/a Smoke Loader
2023-04-20n/aexe 354f09ab4aa3401d7fb2ede018dc47f3a60aee4cd8176caa9d94313def48daefn/aSmoke Loader
2023-04-20n/aexe c70e59ad1e7a2e1b2b05082a6698c96f55918177bb5dc6fbd45e7a014508424cn/a RedLineStealer
2023-04-20n/aexe 8de8f74e47b18426f68ccb49f8afd065b7c2d260cfaa0a47ace624c7dcbf2769n/aSmoke Loader
2023-04-20n/aexe f2e71a34bcce4dd852402737d9ee44dea3976e07c838da2a6a7f4acde48ec0ban/aSmoke Loader
2023-04-20n/aexe 15ab6aea347377bb7a5b5bea781406f85e56be602fc3c2f309323443626765efVirustotal results 45.71% Smoke Loader
2023-04-20n/aexe d04e02ba8eb29db3d17c69a5dcf4075a020eb79a15e7329fe373c60735bbb680n/aRedLineStealer
2023-04-20n/aexe 20270288197fbbe9b70f423924d7ecebce2798853a9a13bf115d1c86fab2e713n/a Smoke Loader
2023-04-20n/aexe f17263a83ea1c51f172cf8021695a62904228bcc94c76a4f3aee92aa11d1531en/a Smoke Loader
2023-04-19n/aexe 070f7bb8630046f88c04f87a3416d713b66f5e75b84a65096561c322c4b60018n/aSmoke Loader
2023-04-19n/aexe 405c1ad5dc6fcd07d88d0efe7d587ca21d6e02c4b74bc53c13017d2d4f648564n/aRedLineStealer
2023-04-19n/aexe b0dc4433c10d74c9f443ad90f78acc99f2f6faca9e8fb849a94ed916303d2e9bVirustotal results 58.57%Smoke Loader
2023-04-19n/aexe 6a31368693cd06e5311210b937e8a3921ebdf4470f9e96761738cd84c083398eVirustotal results 57.14% Smoke Loader