URLhaus Database

You are currently viewing the URLhaus database entry for http://45.66.230.149/offer/notepad.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2679757
URL: http://45.66.230.149/offer/notepad.exe
URL Status:Offline
Host: 45.66.230.149
Date added:2023-07-10 06:33:06 UTC
Last online:2023-08-27 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-07-10 06:34:07 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 18 days, 16 hours, 30 minutes Bad (down since 2023-08-27 23:04:47 UTC)
Tags:64 exe LaplasClipper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-30n/aexe b6e2f26fea81267dc7b39b4f919083c8c8be5ff233a5c3acca6e1339d5bb21e2n/aLaplasClipper
2023-07-25n/aexe 17ca2de661fa07dd83a55a5005c61eb8aee1e9cab56e9a13bc36a27f4b785554n/aLaplasClipper
2023-07-21n/aexe 6bbcf743fa00cfa33aa60a923d319850111d610b44cfdbe1b5dc6c672f177a8fn/a 
2023-07-19n/aexe 4f7f72d5fa0dbdd886de53c3e9bc01cd76bbb94d8d3b0d1deba3eb56d84f1ea4Virustotal results 15.49% 
2023-07-17n/aexe b20d74c759e6d677148c3cf1ddac1056631d69ec738f098d2c8103782d8d82c6Virustotal results 21.13%LaplasClipper
2023-07-15n/aexe 807f54c88592025c02077930259ed3a4c6a3e216a8d53350bbebcb5c597bab2dn/a 
2023-07-12n/aexe 298bdf9042629b42e761f52949926d52acd55239181021fd78040bff32678e4an/aLaplasClipper
2023-07-10n/aexe 77530f67cff4fc2456c0b27abf28d1ab1f4f10fd9be039783adfa25ed1f7f196Virustotal results 25.35%LaplasClipper