URLhaus Database

You are currently viewing the URLhaus database entry for http://103.133.108.160/document/rundll32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1639053
URL: http://103.133.108.160/document/rundll32.exe
URL Status:Offline
Host: 103.133.108.160
Date added:2021-09-22 06:00:08 UTC
Last online:2021-09-25 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-22 06:01:06 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 23 hours, 58 minutes Poor (down since 2021-09-25 05:59:54 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-22n/aexe e596ac1dd5978ef67f061190fc9fb647a4497429c63ea621eb2dc3fe024af7aaVirustotal results 28.79%Formbook
2021-09-22n/aexe 2f086810181af89d5d29a30f5eafcc60efdd2dd3f68292dd3acff64fc92a547an/aFormbook
2021-09-22n/aexe 028243057c6d4a300f7aa0d8553039fc17137f4d552082771dbb036550a74a63n/aFormbook
2021-09-22n/aexe 1cab3a395f0da98681e97fe13c2d17415d49be182f5eb8719a5f260afbd150b8Virustotal results 26.87%Formbook