URLhaus Database

You are currently viewing the URLhaus database entry for http://79.137.192.18/newmar.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2724517
URL: http://79.137.192.18/newmar.exe
URL Status:Offline
Host: 79.137.192.18
Date added:2023-10-23 16:02:13 UTC
Last online:2023-11-03 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-23 16:03:06 UTC to abuse{at}lethost[dot]co)
Takedown time:11 days, 3 hours, 24 minutes Bad (down since 2023-11-03 19:27:46 UTC)
Tags:exe glupteba link LummaStealer Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-02n/aexe 3b7f28a994da86db40f924af3024108e31f55d7fc1fd0a98348daf963a2c65cdVirustotal results 59.72% Glupteba
2023-10-31n/aexe a179ba5bfb90fc8260e11141698050f23487888f1e5d85ff517fa8be1051ceban/a Smoke Loader
2023-10-29n/aexe 6aee985525aef643dda7fc0ac2b6c46dcbfe0d10cd127453fa5e1927441b3644n/a 
2023-10-29n/aexe a1886f685166d4be80d54dfc12e8b369deb4384b249e6aa60e7f8c7d02816191n/a Smoke Loader
2023-10-27n/aexe 896142c5f46f8890805bf33993e952ce267d3c7b895695391beba9baf57a2860n/a Glupteba
2023-10-26n/aexe 0ff5066a1c9caf9db55ddca514049faa9badfd6bee0a6e8ba825ee8198b65efbn/aGlupteba
2023-10-25n/aexe 5c2b4e332af8aebcad025d8c58ae6d643bffbf4b4c69ffd801fd9f38ab98da05n/a Smoke Loader
2023-10-25n/aexe 4a6db4730d885be4e893ff633040523942225198e923cea63de2a772c88e7d12n/a Backdoor.TeamViewer
2023-10-24n/aexe b13f3f708d62bbfcbd90f59d761fb5b518ba402c88f095efdf29c51706ef613bn/a Backdoor.TeamViewer
2023-10-24n/aexe 402e27610cc92a63c480eb4566fc350328da856bb809a146c821fcde0496a712n/a 
2023-10-24n/aexe fdf4a095842205019610d68c054cd30e9c6e859ec8f6492c5b83c2227f3e5b1fn/a 
2023-10-24n/aexe 3ff3e11128ead9eca87a33ac9bc9453cb8450212c0a002bd464243188a3d2f03n/aLummaStealer
2023-10-24n/aexe def5feed42fc356d4590a40e2a44ba163c44fa7f689c975f00dc0554613400b5n/a 
2023-10-24n/aexe 08e3325fc4e8290185758d0015abcab6d5327e0ae4dd90d49d77f94c007682f8n/a 
2023-10-24n/aexe 20ea338af45c4221e0ac33de59e84a3cf0d0eed2f609fbad4d3227f5131de0e2Virustotal results 55.71%Backdoor.TeamViewer
2023-10-24n/aexe c0ac5d1a8ecec0939b5fce4b90a3c08ca17bd656293f4f064cec7d44e84d0601n/a 
2023-10-23n/aexe ebf0fbb2d06f3a42839c341b052cfe7b8b4e0b7e93a5f37a3c426f27a762e63aVirustotal results 59.72%Backdoor.TeamViewer