URLhaus Database

You are currently viewing the URLhaus database entry for http://45.9.74.80/yuha.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2672592
URL: http://45.9.74.80/yuha.exe
URL Status:Offline
Host: 45.9.74.80
Date added:2023-06-27 05:32:16 UTC
Last online:2023-08-01 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-06-27 05:33:15 UTC to abuse{at}lethost[dot]co)
Takedown time:1 month, 5 days, 13 hours, 45 minutes Bad (down since 2023-08-01 19:18:42 UTC)
Tags:Amadey dropped-by-PrivateLoader FruitMIX RedLineStealer link Smoke Loader link smokeloader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-30n/aexe b5908f286ad5b64cc5d098365cf57db32a41b5466d0e5a329195b4bbcfc63f29n/a Amadey
2023-07-28n/aexe ee366039716c1ca70c1c1744faaf2aeeae8d780c6bbd438cc0c1fef3f7a57cc7n/aAmadey
2023-07-19n/aexe dcba1aa4b4d92b68713b03f12985b0b0689055b3921e0273506d23f7e675ff52Virustotal results 62.32%Amadey
2023-07-15n/aexe a75c766167a44c78f3824d28780078cf2cc31522a55372958cefd5f3f093e4c1n/aAmadey
2023-07-07n/aexe abd8284914e8bc1309c13903e7b41b1af552c80598982c9e8fbe35e88eda9315n/aAmadey
2023-07-06n/aexe 86e6d53e0ebe3180ae638fcf23379cc36cdbc26f01ec8aae42744f679a4498d5n/a Smoke Loader
2023-07-04n/aexe 81d2aa64b3f784fc0dab7694d106bedbd193786ab47dd064c0c5a8714d3fcaffn/aAmadey
2023-06-30n/aexe 68af9af3506c7a35ef60026b6662cbc1fda0b36007a6eb48a974e4d7574db21fn/aRedLineStealer
2023-06-29n/aexe 6aa14b8612361f8cd34a86edcf341aaee819fb9a0cc18d51165e52afdcbe5e60n/aAmadey
2023-06-28n/aexe 13a43acaf411468a1ddfa5f221464f0ead5221a8694bb1027273206ecfa2e336n/aSmoke Loader
2023-06-27n/aexe 64c99e86f8722c5b825250b3302a2eafc652a09108a3213e124f173f10be2eebVirustotal results 42.25%Smoke Loader