URLhaus Database

You are currently viewing the URLhaus database entry for http://79.137.192.18/latestmar.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2729130
URL: http://79.137.192.18/latestmar.exe
URL Status:Offline
Host: 79.137.192.18
Date added:2023-11-09 06:46:12 UTC
Last online:2023-12-02 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-09 06:47:05 UTC to abuse{at}lethost[dot]co)
Takedown time:23 days, 14 hours, 18 minutes Bad (down since 2023-12-02 21:05:59 UTC)
Tags:exe glupteba link Smoke Loader link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-13n/aexe 394806d79ea2ea4c7ee7af56633e23deee66847483e4d5fc7d0db558aed2c481n/a Smoke Loader
2023-11-12n/aexe fa90294c2cd7c12d68524c55cc5ed0e3276d0a7bbce8fedec1e0cf679e521298n/a Glupteba
2023-11-12n/aexe 8c5a38887768a98da1ba757c359a2f24b137ef9b78c7b5ba8383d999582d1b2bn/aStealc
2023-11-11n/aexe 8559eef75d44d48a5987571139ce0f791879fe3a7a21761a68f5f9dbac1ff216Virustotal results 62.86%Stealc
2023-11-10n/aexe 3e720c51e608d3126d9181df7df3333d89957d56d13d2b6686dd99fded9ee442n/a Smoke Loader
2023-11-09n/aexe 60861a072ffc6b404ae640f7270e6d36afd5f4b0911866598be0800da4c16ab8n/aSmoke Loader