URLhaus Database

You are currently viewing the URLhaus database entry for http://185.172.128.69/latestumma.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728732
URL: http://185.172.128.69/latestumma.exe
URL Status:Offline
Host: 185.172.128.69
Date added:2023-11-07 08:09:10 UTC
Last online:2023-11-10 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-11-07 08:10:23 UTC to abuse{at}tnsecurityl[dot]ltd)
Takedown time:3 days, 12 hours, 25 minutes Bad (down since 2023-11-10 20:36:03 UTC)
Tags:glupteba link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-10n/aexe 3fb42de7bef728db9db776ce892a5893f84b24c433253988d849c514a4008b67n/aSmoke Loader
2023-11-08n/aexe 0d56a6315fa87dedf33b91c34e70ace7cf2913fc4f30976dc9b34a974d30ca31n/a Smoke Loader
2023-11-07n/aexe c39a990dc179128a4d4136de519676636ad393b77f43913fb0d5c238b20c95d7Virustotal results 60.00%Glupteba