URLhaus Database

You are currently viewing the URLhaus database entry for http://185.172.128.19/brandmar.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2732125
URL: http://185.172.128.19/brandmar.exe
URL Status:Offline
Host: 185.172.128.19
Date added:2023-11-20 05:37:22 UTC
Last online:2023-12-01 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-20 05:38:05 UTC to abuse{at}tnsecurityl[dot]ltd)
Takedown time:11 days, 15 hours, 2 minutes Bad (down since 2023-12-01 20:40:23 UTC)
Tags:32 exe glupteba link RiseProStealer Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-01n/aexe cc4dfe3338f1a44d1309b80570b37618b33f62053e4b35f118764c85ca0154cbn/a 
2023-11-22n/aexe 3ce85883196c60029ea274d02b47b099e5d8b0f8b8acee778605857a51ee72e2n/a Glupteba
2023-11-22n/aexe 9e532f050511a7eb84be36d745cfa69c4329bb7dd79017c4275ad13a48483e6dn/a 
2023-11-22n/aexe 0cb132900bac4ee478365d58a1dc5bce8116be18b708be7426c9d2cbe89ccb98n/a 
2023-11-21n/aexe 02c6afc6297dce33b1a7b9db1be1002387d0744222471657c224b763b06e03c0n/a RiseProStealer
2023-11-20n/aexe 121a9ea644073f820645f34c67bd159aff5a29cec51269cdc07bf4dad0249f30Virustotal results 62.50%Smoke Loader
2023-11-20n/aexe 4abd157267e0e423d698f49a60011c7d0c9fc30e21585ff42f974909e37bde4dVirustotal results 69.44%Smoke Loader