URLhaus Database

You are currently viewing the URLhaus database entry for http://13.53.52.84/run/binok.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1339587
URL: http://13.53.52.84/run/binok.exe
URL Status:Offline
Host: 13.53.52.84
Date added:2021-06-08 08:00:53 UTC
Last online:2021-09-30 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2021-06-08 08:01:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 months, 24 days, 14 hours, 45 minutes Bad (down since 2021-09-30 22:46:27 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-30n/aunknown 484d539e61ded163703baf3ef38dc362659a3977ec299b47729296e0f62afa2en/a 
2021-09-30n/aunknown 69a28f182d68623b20207139598772021f3ce1f97ec13f69fdbb399db7b694een/a 
2021-09-30n/aunknown 6a4cdb4ac2fedc0166ec2f604c5420ec767b140aa6f59434dc1a6f90a55576cbn/a 
2021-09-30n/aunknown 5d14022d10d6e716cef32a0d93eee2133b923fb17ef549c55df08701b5574ab8n/a 
2021-09-30n/aunknown 4aaab3d874147716f7fc9691735974a7a37e6432f8cdd2842c828c8cc3a76178n/a 
2021-09-30n/aunknown 1596b762f697e7c5649cea7486fda76f16e3f20289be17320f497ed18b8fca3fn/a 
2021-09-30n/aunknown 31168abfcaab53940821d2bf5b0f324955a1f2a50c8a6f0d4b58525d8be623a0n/a 
2021-06-08n/aexe 603a59ae862f03407f0f1b22b44f4d233ec94dcdbaf5702bfc655ae4d5872184Virustotal results 34.29%Formbook