URLhaus Database

You are currently viewing the URLhaus database entry for http://107.173.191.112/cdg90/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1735318
URL: http://107.173.191.112/cdg90/winlogon.exe
URL Status:Offline
Host: 107.173.191.112
Date added:2021-11-01 09:22:04 UTC
Last online:2021-11-08 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-11-08 09:25:19 UTC to abuse{at}colocrossing[dot]com)
Takedown time:7 days, 4 hours, 27 minutes Bad (down since 2021-11-08 13:50:34 UTC)
Tags:AveMariaRAT link exe Formbook link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-05n/aexe 204dca3bdab875faaa44fc19dadddf3a76eecf3bf27869b70e6c99dfd8c59070n/aFormbook
2021-11-05n/aexe 01937fda97b740f957d7d09b86a37bdcce259b01327599c9d9afb212dbe9b796n/a
2021-11-04n/aexe 5853fea34c2f36ca0f6d90a85b9b6d3e8d362f0a32d27bf4926b8d4543ad95b7n/aFormbook
2021-11-03n/aexe 6b889ef8b43f316066faf4f225e192e2390f3dd007bd87ef371ddf0aae8745dcn/aFormbook
2021-11-03n/aexe e1f8c7d02c06ad8a4d9a2e46a9c9d73e8cb95c854ca4c0558ae8c83e11f8c63bn/aFormbook
2021-11-03n/aexe 736330aaa3a4683d3cc866153510763351a60062a236d22b12f4fe0f10853582Virustotal results 4.41%Quakbot
2021-11-02n/aexe efe9b63a36e528968686974ee0afe6097d100ff4aa5dfaf4f6ee48a9d3f090bcn/aFormbook
2021-11-02n/aexe 64964b0f5fc8246845fa84482e015a5dbc465533e016c34eb015d29cfbda626bn/aFormbook
2021-11-02n/aexe d42bcc47988047ff1c55d282cf4396b9bb46b00cac8647073664e6635c947c39n/aAveMariaRAT
2021-11-01n/aexe d0d08195d6779cadf6750741740960f4956110f505a63c1109427449df51b13en/aFormbook
2021-11-01n/aexe 3c9984e534636c34f7a22ccbbfb1c06baa5a6f16883eb77a65ac615dffa24f16n/aFormbook