URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.213.2/hgg/loader2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1722926
URL: http://198.23.213.2/hgg/loader2.exe
URL Status:Offline
Host: 198.23.213.2
Date added:2021-10-28 10:05:05 UTC
Last online:2021-11-05 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-28 10:06:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:7 days, 23 hours, 44 minutes Bad (down since 2021-11-05 09:50:25 UTC)
Tags:exe Formbook link Loki link Neshta opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-05n/aexe d6a80b55918ee355db02ac1aae19bcede30c3d09598cbc60499ba7a29c9de22bn/aFormbook
2021-11-03n/aexe 1b6ff162d06ef0d1df78ada89bc99374b76362c5693b625ef9d46c9ee50e5309n/aNeshta
2021-11-02n/aexe 115a084d9aa48d9bb0f37d760c8997e3ec905a5b4adad3eeba9c8b18e44e9408n/aFormbook
2021-11-02n/aexe 3c0c81da2bf8ab68ce917e48365343043e29a597a0b19cd24b952fc1cab94249n/aLoki
2021-11-01n/aexe ccf480117064337bc042c67f7dc0a65625c733a692cf7cfed206c0037a3067cbn/aLoki
2021-10-28n/aexe 08c2207b023f1d2e65be57b75a4395908b2474b1f244d8f53d43914f94b7be8dVirustotal results 36.76%Formbook