URLhaus Database

You are currently viewing the URLhaus database entry for http://45.9.74.80/offer/toolspub2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2666467
URL: http://45.9.74.80/offer/toolspub2.exe
URL Status:Offline
Host: 45.9.74.80
Date added:2023-06-19 17:41:05 UTC
Last online:2023-07-15 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-19 17:42:06 UTC to abuse{at}lethost[dot]co)
Takedown time:25 days, 22 hours, 24 minutes Bad (down since 2023-07-15 16:06:19 UTC)
Tags:32 exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-13n/aexe f22fa7920f7729484a868da80587b56a9d7fef0e1309d58760cf5daba8374a65n/a Smoke Loader
2023-07-12n/aexe b73ef06e30578a4f9144826d86b5e558ccda91cbf9ac9c9243239825398427a8n/a Smoke Loader
2023-07-06n/aexe 267de067a0574bc4611f6f5a92b65b20d4de66b83cdebf71177dbc89fc82d37cn/a RedLineStealer
2023-07-04n/aexe bc7418fdcc8bc724424f4fa4db1e21b4c1d1675092663c5f88ee285bc98205fbn/a Smoke Loader
2023-06-30n/aexe 7a33f13cab7536657d3e8c34d5d59b6f4eec7b479f1e852fe675b518e4138222n/a Smoke Loader
2023-06-26n/aexe 6a9bf2803c256df7abd2017b1720f254afcb863612abd9f39da492141ea86dd7n/a Smoke Loader
2023-06-24n/aexe 6ba96ab9e09801ed43485fae7797223a383554397e8de1ea71912cb843794bf0n/a Smoke Loader
2023-06-23n/aexe b55102d7d8864344cd3a64bef07b837777e1ee2d2c0bcc9d94a5e4c73aefcbe6n/a 
2023-06-21n/aexe 58421a93e1a0fdd8a1caacc59680c5eb95fc0926a9fbaf678c10b68ab6ef6042n/a Smoke Loader
2023-06-20n/aexe 572e7488a0294472f88e9fce86c71a633367d054c15024bf8fa034c1aba70b1eVirustotal results 43.66% RedLineStealer
2023-06-19n/aexe 40ebe2f864e61a190e83905b6dd90a640139852e3d1ade8256d5b53cab4b5511Virustotal results 43.66%Smoke Loader