URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.14/so/va.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1454395
URL: http://136.144.41.14/so/va.exe
URL Status:Offline
Host: 136.144.41.14
Date added:2021-07-14 16:49:03 UTC
Last online:2021-08-06 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-14 16:50:02 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 12 hours, 9 minutes Bad (down since 2021-08-06 04:59:17 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-31n/aexe dde0d8980f77e3569f9d6c5e0c439e8dd8e2bba5fa2ae4d029ddcc4c1f3da134n/aFormbook
2021-07-31n/aexe 09599ff21ddd0f31d3d708569e2fa57a8c4585e22fb08a42a8ece1af052644c3n/aFormbook
2021-07-31n/aexe bd94addc9c8a362575b6f16196eb0bb9aabc6d68669421054c4e9ac0ad7b5aebn/aFormbook
2021-07-14n/aexe c36fa12719f133f394b113938584b1d693d4741df4e40d34958dcee239ecd153Virustotal results 30.43%Formbook