URLhaus Database

You are currently viewing the URLhaus database entry for http://file-file-file2.com/downloads/toolspub1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2821472
URL: http://file-file-file2.com/downloads/toolspub1.exe
URL Status:Offline
Host: file-file-file2.com
Date added:2024-04-22 06:18:17 UTC
Last online:2024-04-26 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: dms1899
Abuse complaint sent (?): Yes (2024-04-22 06:19:13 UTC to abuse{at}cishost[dot]ru)
Takedown time:4 days, 5 hours, 29 minutes Bad (down since 2024-04-26 11:48:55 UTC)
Tags:exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-24n/aexe 3460da28a0587dedb4be574e4b26f25c807d42816562e2abdf61a34c1ac68b37Virustotal results 37.14% RedLineStealer
2024-04-24n/aexe afd8d796e3b6dcfb948980d5f9c439bb1598776e5eb67f1c38943b48c413e27fVirustotal results 40.85% Smoke Loader
2024-04-24n/aexe eca62d3dfad6ae0eef6f384360749315a305139c6db17435754a44c2b30333cen/a RedLineStealer
2024-04-24n/aexe a74017849283e1e83afad2f5aefc3a5fb9ced3a3f380130452c35d39161f1785Virustotal results 34.29% RedLineStealer
2024-04-24n/aexe d97c0af5b63101eaa727f712ff96a91bd2259104cf63e7d7cb8a6ebd15bf8cedn/a Smoke Loader
2024-04-24n/aexe ff64b6a65f623bee3a6c72797ca449545801deea098d0209e7bd4f2abd4bcaa6Virustotal results 40.00% RedLineStealer
2024-04-24n/aexe f25fb3950d39d7724ce8e66b5f119fbcaf29c4b2298370a9836522c558fb0899Virustotal results 39.44% RedLineStealer
2024-04-24n/aexe ae31150a88972baaef828058a5c70ccba8c92e2564b5138b4091ce23e98a7182Virustotal results 38.81% RedLineStealer
2024-04-24n/aexe d82dd6ad1da44d87bb0a019a7c2b389a5bf234c67d0a337196f4856c64ad895aVirustotal results 38.03% RedLineStealer
2024-04-24n/aexe c29cf1b69013a305ecac54d82e91a65c1556c8e7e07a93db9bee53f5f0f63999Virustotal results 35.71% RedLineStealer
2024-04-23n/aexe 5cb8d9d3cd87aa51be2989b76f6ae25a92b6960eb6ff16742958bfbb445c1604Virustotal results 41.43% 
2024-04-23n/aexe 69e4203d32d5f071be287f367d0a42050eeb6c2ae9483cc12738d88d2f221f9eVirustotal results 38.57% Smoke Loader
2024-04-23n/aexe bccce734cff751f6c6d85b05f30af7be392f67a61e50ec5bddba56abd72e3497Virustotal results 39.44% RedLineStealer
2024-04-23n/aexe 5c48b2eb1c3d8c5b4c8dab1a0a74ebc685688095ddce940566d9337cf6484968Virustotal results 40.00% RedLineStealer
2024-04-22n/aexe 1d5fe89aae579ea253d121deb90c9a61f94ddab13ff51f58f939a57f0edab73eVirustotal results 45.07%RedLineStealer