URLhaus Database

You are currently viewing the URLhaus database entry for http://3.36.109.92/win/xlss.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1138641
URL: http://3.36.109.92/win/xlss.exe
URL Status:Offline
Host: 3.36.109.92
Date added:2021-04-19 07:05:07 UTC
Last online:2021-04-21 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-04-19 07:06:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 52 minutes Poor (down since 2021-04-21 13:58:32 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-20n/aexe 75f30f3c9b6e42126a4b1cf4c86a177a1f2784c5cafcb58c6d586cd5f3f67938n/aFormbook
2021-04-20n/aexe 18609513507af97f13c81c7e733175ca027c4957f401e61d6654fc2ee7b4cf8cn/aFormbook
2021-04-19n/aexe e1339c4548f73e4f250fed46d56bbce84491ca122aed7527731bb8d72df83e11Virustotal results 8.70%Formbook
2021-04-19n/aexe 5b19c5b2854cf7d4ed344ff7539b38caec397d6a3002a7219b2fbe0b7c73f455n/aFormbook
2021-04-19n/aexe 1d83a24be501df5dc4902f068a42033ab35c8546471dc627b5ebc452ce5da76fVirustotal results 26.47%