URLhaus Database

You are currently viewing the URLhaus database entry for https://api-alajman.com/tmp/index.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711889
URL: https://api-alajman.com/tmp/index.php
URL Status:Offline
Host: api-alajman.com
Date added:2023-09-15 12:22:06 UTC
Last online:2023-09-15 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-09-15 12:23:05 UTC to abuse{at}zare[dot]com)
Takedown time:10 hours, 18 minutes Good (down since 2023-09-15 22:42:01 UTC)
Tags:dropped-by-SmokeLoader Smoke Loader link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-1502269dec.exeexe aa918d4dd7706951fc290b6a5d3ba0e48acc5443056894ee3aad1baa52f412ban/aStealc
2023-09-155f7e903f.exeexe 56be912ce754d75f3385dab925ee34d9a0a1e07fe841c6a2e9adafa8021c99bcn/aStealc
2023-09-1562d2f9c4.exeexe 9e7c8aea93412acc8d8de3a956e8485a86caf40c626b2abd491bd5404df1bfbbn/aSmoke Loader
2023-09-15f26ba517.exeexe 831a4d32e5d5417d5c6c81966b3aaad36b44f6d52b18d5731e78c099faf406e3n/a Stealc
2023-09-157e0b5f1d.exeexe 06f3c31343921c5f63bc0803569db1a31f0ecdf6029f167dcc234754eabacc9bn/aSmoke Loader
2023-09-150779605d.exeexe dc7e2649445fbdb28a271c6800ed2540e1c25ebf52942f581d297c81a8624bcdn/a Smoke Loader
2023-09-15196f2cc8.exeexe 8bbbf51d4c5404915d1b306121e0226d1f23e88acf635c8cb4f4461dbe142838n/aSmoke Loader