URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.122.140/file/loader2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1659293
URL: http://192.3.122.140/file/loader2.exe
URL Status:Offline
Host: 192.3.122.140
Date added:2021-10-07 08:10:05 UTC
Last online:2021-10-21 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-07 08:11:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:13 days, 22 hours, 52 minutes Bad (down since 2021-10-21 07:03:14 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-15n/aexe c6106fc0a5a8a0fb4a2245bd159b22ed22ec40840826b51b585f78f97f860be8n/aFormbook
2021-10-14n/aexe 4a07b3b4c08db64e0aa91b63b89bdf438814a5236de328efcb11fd9a78ed19bdn/aLoki
2021-10-12n/aexe 90aea5afb79d4a06dd87604c0e77067079fe149ba7d9c6db2308b64d7ad4d641n/aLoki
2021-10-11n/aexe eb107daa1a87d192430ab9abefbf715b0ac5dd8e3c1aa78d088b049c8359a372n/aFormbook
2021-10-07n/aexe 9fd3ea298e67c87b5da5cf7806e597556d3a113c5b64f1a98041f2a8b303e81an/aLoki