URLhaus Database

You are currently viewing the URLhaus database entry for http://sakentoshi.ru/download/mstsc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2716568
URL: http://sakentoshi.ru/download/mstsc.exe
URL Status:Offline
Host: sakentoshi.ru
Date added:2023-10-05 08:58:07 UTC
Last online:2023-10-25 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-25 21:25:07 UTC to abuse{at}simplecloud[dot]ru)
Takedown time:27 days, 15 hours, 34 minutes Bad (down since 2023-11-02 00:34:01 UTC)
Tags:exe opendir Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-01n/aexe 4d311d7c8d8233168a120ce059b0e6376033ef73a2f5504f00f5a288d09df133Virustotal results 40.28%Smoke Loader
2023-10-31n/aexe 5d72dd3ea91f2f0c953a68078201bc75ef4bc71756e83261cd03177f60dab70fn/a Smoke Loader
2023-10-31n/aexe 9461d527794959513d16803740d0ea4f8e47af9bd6667e101f469076eb848473Virustotal results 0.00% 
2023-10-26n/aexe 693708303e3c2e4635296abd30ee4bf0caf248bb6f9ec3602f09e35b0aa698d9n/a 
2023-10-10n/aexe d3bff8ee2566c13a391cec24be134d3d04ee65b87529e1c98caf93b5b559fce4Virustotal results 39.44% Smoke Loader
2023-10-10n/aexe efd2a3ddbf2b7e68a8f3359865dfcd6fd1403fb7d1dc945aa7aa4ccb50284ee7n/a Smoke Loader
2023-10-06n/aexe ebbf474d69519b7ded60c1dab807dab492c33d9caf76e6495c2ee92be573011en/a Smoke Loader
2023-10-05n/aexe 9a528b2b31d9d59018878fdf3b9d8db235df606500c67a4b8be3075701b014fcn/aSmoke Loader