URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.75.136/set/set.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1722896
URL: http://107.172.75.136/set/set.exe
URL Status:Offline
Host: 107.172.75.136
Date added:2021-10-28 09:38:05 UTC
Last online:2021-11-05 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-28 09:39:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:8 days, 2 hours, 29 minutes Bad (down since 2021-11-05 12:08:43 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-04n/aexe 62700ea2d5c2d47662a314b0af9d02672a7766d9c8d9d9eacb51b53705e869b3n/aFormbook
2021-11-03n/aexe 8b401bedd47d2f15827ae1082d0d8bb90b1280e80051fa3727ee3f4a77843704n/aFormbook
2021-11-02n/aexe 6c505769c3fd238742b1a9ae5620afc9c4c24e37c5e749feda8eac24417faa23Virustotal results 37.68%Formbook
2021-10-28n/aexe e0d91566226df326eacb5b23fc65f8f5a18fa982c662c169e0b4c9cde3d8898bVirustotal results 29.85%Loki
2021-10-28n/aexe 0aa08d86a002c9ae17de017777dbbe5704c31ab2351737244c11d2aac1a5ff0dVirustotal results 28.36%Loki