URLhaus Database

You are currently viewing the URLhaus database entry for http://mktrex155.xyz/ldx111.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3072059
URL: http://mktrex155.xyz/ldx111.exe
URL Status:Offline
Host: mktrex155.xyz
Date added:2024-07-26 20:08:05 UTC
Last online:2024-07-27 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-07-26 22:13:07 UTC to abusecontact{at}deinserverhost[dot]de)
Takedown time:15 hours, 58 minutes Good (down since 2024-07-27 12:07:22 UTC)
Tags:CoinMiner Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-27n/aexe 8bac155a33708bce44afaa1c38363701ac89743577edef0b31105cde0eb7153bVirustotal results 45.33% Smoke Loader
2024-07-27n/aexe 87f3eab16a49cdb0bdfe1906ad5e0989a057a3b253f2622dff125986f813aedeVirustotal results 44.00%Smoke Loader
2024-07-27n/aexe 80a4325072a8d0587da28929a497d615433addcab45caf75ac0e75d28b6d0dffVirustotal results 41.89% Smoke Loader
2024-07-26n/aexe 2eb9d2a67aa9761b996f932affd2deab03145b56b96cb9f9ceebfbffc9e866a2Virustotal results 44.59%CoinMiner