URLhaus Database

You are currently viewing the URLhaus database entry for http://185.172.128.69/ummanew.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2730182
URL: http://185.172.128.69/ummanew.exe
URL Status:Offline
Host: 185.172.128.69
Date added:2023-11-13 06:34:20 UTC
Last online:2023-11-29 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-13 06:35:06 UTC to abuse{at}tnsecurityl[dot]ltd)
Takedown time:16 days, 5 hours, 51 minutes Bad (down since 2023-11-29 12:26:56 UTC)
Tags:dropped-by-PrivateLoader glupteba link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-16n/aexe f4af92120cba0d2e138483300e286361b55a3ef49f73c3f01178d5961ecba808n/a Glupteba
2023-11-16n/aexe aac1c546045c66827a679967199bc7fd1457bf72424540e10f93dea9e687f7e9n/a 
2023-11-15n/aexe 991c58c378f5d7b1877bcd5244165e8be9ce2c2b60ba2573abd7412676228833Virustotal results 25.00% 
2023-11-15n/aexe 4291751e866446160c8be6dfe03c84be165c0b09da933e221692794e4dd4b947n/a 
2023-11-15n/aexe 4952901ca402d8ebf6b5825bec872eda5078027a28a9ac98473f64ca7f487259Virustotal results 13.89% 
2023-11-15n/aexe ae12645a616c6a3f8fcd341208093c17ec03da65c882fdbd36b0620766bf6b3cn/a 
2023-11-15n/aexe d18a974edd44b574872865bc90188d826f72c5185ad6d0eb2fb39da633b5efefn/a 
2023-11-14n/aexe ca7b701772c2bb508b29738bcc91864df7ec41cca59b8acca02ebd5336633cf8n/a 
2023-11-13n/aexe 7ef4fce93908840ce8083e0a717e82f80720e5fa5d3b7820f3d6ceb9c23bfbbdVirustotal results 61.11%Glupteba
2023-11-13n/aexe 4d51e1dc59c149003604bbd8ddaa425ef767789c19e2d3d3d7db2b4e530f8b4aVirustotal results 62.50%Smoke Loader