URLhaus Database

You are currently viewing the URLhaus database entry for http://45.9.74.80/super.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2706900
URL: http://45.9.74.80/super.exe
URL Status:Offline
Host: 45.9.74.80
Date added:2023-08-25 05:11:15 UTC
Last online:2023-09-01 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-08-25 05:12:14 UTC to abuse{at}lethost[dot]co)
Takedown time:7 days, 8 hours, 37 minutes Bad (down since 2023-09-01 13:49:31 UTC)
Tags:Amadey dropped-by-PrivateLoader Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-30n/aexe e3cc5f126472497826ad34d0e0348d3d0a0dea126d5ec73c5ed1a6eaf8f6272dn/aAmadey
2023-08-27n/aexe 2dea8cfcd31f4675d5462c385139b59528759bee88aec34ed9d0757d289e7a34Virustotal results 66.67% Smoke Loader
2023-08-25n/aexe dc8ce8ab78c6cdddfd1ccd40a3b8d4d177a9ab9de871bbf9e81c54b97e29a342Virustotal results 66.20%Spambot.Kelihos
2023-08-25n/aexe 6531b801cc6cbf4139616803f9d43e9b886eed6c9ca82b86bb9c461c50f673a0Virustotal results 65.15%Amadey