URLhaus Database

You are currently viewing the URLhaus database entry for http://pofix.red/upd/index.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2831406
URL: http://pofix.red/upd/index.php
URL Status:Offline
Host: pofix.red
Date added:2024-04-29 13:37:17 UTC
Last online:2024-05-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-05-02 07:34:06 UTC to abuse{at}uninet[dot]net[dot]mx)
Takedown time:3 days, 4 hours, 35 minutes Bad (down since 2024-05-02 18:13:15 UTC)
Tags:dropped-by-PrivateLoader Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-0246b03b92.exeexe e787e9b3eb07676a4848cb9ff1dad9a19a5b3aa11a220b2ba3d447ac6680abebn/aSmoke Loader
2024-05-010b3f1e5b.exeexe cd18f6507d1618aeab81f86569c00b3b38d84bd18202525e93dd37e7f2d1b548n/a 
2024-05-01ad50f549.exeexe bce1ec6a85c3c28e516d68f23949e213fc02126cee986796be7658b1d7a082c4n/a Smoke Loader
2024-04-30f573cea6.exeexe 538af0e39f24f16e4e52cad03295a359304d8f458c1fe18d0681e884112f2185n/a Smoke Loader
2024-04-303d49a825.exeexe 74e41f3d6f09eea1f0b6fcc6dd6a4c39f364d6468740e996be01172264a37169n/a Smoke Loader
2024-04-2983328b60.exeexe 546d7f26d8b2a42b4a917e3642c2fffa89a1be3a41795da4ccf8afb2e0f417e8n/a 
2024-04-292aa22576.exeexe 1b7e2ddcacb26f4c02291ff2b977a1394e76f36d4d773e67d7af33a1eb74118dn/aSmoke Loader