URLhaus Database

You are currently viewing the URLhaus database entry for http://94.232.45.38/ttt01.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2801300
URL: http://94.232.45.38/ttt01.exe
URL Status:Offline
Host: 94.232.45.38
Date added:2024-04-04 17:02:04 UTC
Last online:2024-04-14 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-04-04 18:58:06 UTC to panchenkodim{at}gmail[dot]com)
Takedown time:9 days, 23 hours, 59 minutes Bad (down since 2024-04-14 18:57:44 UTC)
Tags:dropped-by-SmokeLoader PureLogStealer UACModuleSmokeLoader zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-10n/aexe 615da643b5f2bc74686bfe02ab93664c9d203706b4d9941820751f19def57685Virustotal results 25.35% UACModuleSmokeLoader
2024-04-04n/aexe 91a45c416324ed3a8c184e349214e7c82d6df0df4fe6d06f3c7818c0d322373bVirustotal results 68.06%UACModuleSmokeLoader
2024-04-04n/aexe fe3a180c6f2b60573884dffd9ed91d858fc7c98fecf98218fd1d9e51256734b0Virustotal results 36.11%PureLogStealer
2024-04-04n/aexe e346f2c15cb9cb03b4c4d8c28c8a36f06065f4e37ec8de79995fd8526baa851an/azgRAT