URLhaus Database

You are currently viewing the URLhaus database entry for http://18.184.225.160/win/marxlo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1049934
URL: http://18.184.225.160/win/marxlo.exe
URL Status:Offline
Host: 18.184.225.160
Date added:2021-03-06 05:39:05 UTC
Last online:2021-03-10 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-06 05:40:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 days, 6 hours, 25 minutes Bad (down since 2021-03-10 12:05:16 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-10n/aexe 1a358d62b634888521fb303f5b388d72084d2983190f17b0af762b21f176fd68n/aFormbook
2021-03-09n/aexe e0d8da6249a7613a40f6b514cae3b15c22a667b5632f1b8545453e0ca31215ccVirustotal results 15.94%Formbook
2021-03-09n/aexe d2d50893bb4f2c943c32f834cf6c095e5e4f2e7997b543c1012cf0e74ca8adffn/aFormbook
2021-03-08n/aexe a076b3b8f0b77d504ad39226a9f30a04cbe94fb2b163d9173637600166dfe25bn/aFormbook
2021-03-08n/aexe e07c6115d9384a13918a22ac6f22631f78a9f18f8eaf3a945c6ba80ba91d713en/aFormbook
2021-03-08n/aexe 1c66b22efb0bdbad857ae02729fc6354c8279f16ccd393ebfd16456363763fbfn/aFormbook
2021-03-07n/aexe bf6ae876108b5fec915d91bd36d3ccd22c8593be29412521c32a4b3f11a757f0n/aFormbook
2021-03-07n/aexe 855df18b5bb8c92bbd2b960914a6c88874a201cbd5ca656ec9c397870fabb887Virustotal results 10.00%AgentTesla
2021-03-07n/aexe c8aaa220adc918c9972a9c588db765290bf51553bed7da48c604d188136d3073n/aFormbook
2021-03-07n/aexe 42b03868b228a6ad438ae1ec4601d442b7271026a237f37f6ac9db725d08a034Virustotal results 38.57%Formbook
2021-03-07n/aexe 99cfc0e79eca01b80f6b466bd9bf208b821e275b3787cb194d0f2b83d6ffe03an/aFormbook
2021-03-06n/aexe 0e23e210b0a781a42bf7f5fcf1cc95b888c1230c819fe7134f04048a36706124n/aFormbook
2021-03-06n/aexe 17dad12ff05c404eaa01cd849464c0a631051c8ba3056fe171ebfeb9e16915a8n/aFormbook
2021-03-06n/aexe 9f5ee7d9915ac3e6f684c7e22555357b5c43c6ca6cbaca8a974b667b51a3ba51Virustotal results 38.03%Formbook