URLhaus Database

You are currently viewing the URLhaus database entry for http://3.36.91.55/winace/xleed.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1115162
URL: http://3.36.91.55/winace/xleed.exe
URL Status:Offline
Host: 3.36.91.55
Date added:2021-04-14 07:13:07 UTC
Last online:2021-04-16 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-14 07:14:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 1 hours, 34 minutes Poor (down since 2021-04-16 08:48:59 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-15n/aexe 5b7770f02c562dffdbe0cd638e288adba8f340c7231ef30fa2860b7f4b9dfa80n/aFormbook
2021-04-15n/aexe c9afe6904407e9b60e73edf93efbd932b6725f0f4f33306117ffc9854c21cae2n/aFormbook
2021-04-15n/aexe e550a6728acd12e2cb73839ea53cafe12a4d24eec807b29af9396f4dfdf407d8n/aFormbook
2021-04-14n/aexe 15944a88ca237bb17dde16f5ef5a0dc4122576d8dc80f2d28f2b9555464c05bcn/aFormbook
2021-04-14n/aexe ce99378f7bcd95a0441b3572fe948daeb420ec960719761b249b817e5c0cec37n/aFormbook
2021-04-14n/aexe 3a7994df6e69118ca5778366f7dbf26e37430d3b9d20a163ace830e5a1971ce9Virustotal results 8.96%Formbook