URLhaus Database

You are currently viewing the URLhaus database entry for http://180.214.239.85/desktop/rundll32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1673387
URL: http://180.214.239.85/desktop/rundll32.exe
URL Status:Offline
Host: 180.214.239.85
Date added:2021-10-13 09:06:07 UTC
Last online:2021-10-14 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-13 09:07:07 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:20 hours, 54 minutes Good (down since 2021-10-14 06:01:23 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-14n/aexe 89b049bc712096512185d1607a9318c074885b2d5b529e0985dc92cdd94d1f51n/aFormbook
2021-10-13n/aexe 092be1f456b0c24d932d6c4e4c44cfd0c9abc6c0418bf1567e67826cb51aef14n/aFormbook
2021-10-13n/aexe 91a166f9a29ad832c9640078210a47e5afa928ab1a79a7b40d3b358e9c8bc5d5n/aFormbook
2021-10-13n/aexe 9136c283e5029c2f073b706014f6f73b67ead84450267cb5ce0dd26cbcecaa25n/aFormbook
2021-10-13n/aexe 6ffe756ce71f1457d7dd480357f3545f123b750fc4bf30683b59887d491948a7n/aFormbook