URLhaus Database

You are currently viewing the URLhaus database entry for http://3.68.213.164/www/old.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1456753
URL: http://3.68.213.164/www/old.exe
URL Status:Offline
Host: 3.68.213.164
Date added:2021-07-15 14:04:04 UTC
Last online:2021-07-17 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-15 14:05:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 56 minutes Poor (down since 2021-07-17 21:01:14 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-17n/aexe c422b04b5177a83b94f15e8bd6b8eca2e7e91a0c082b5035a7aa4b475e38688cn/aFormbook
2021-07-16n/aexe dbd108633606663ffe38920ce2c74dee5e68fd23f510e644cfd358271099942cVirustotal results 24.64%Formbook
2021-07-16n/aexe 28a0ad307023870bf0337867f6ef3f75fbb74bb71d768db0515c96d8d8c6d787n/aFormbook
2021-07-15n/aexe 8fd4cf94ee8683475a5fa775b37afeaeef36e4791fd1e3ecfde74cfaaf498106Virustotal results 28.36%Formbook