URLhaus Database

You are currently viewing the URLhaus database entry for http://107.173.191.111/ghy77/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1813698
URL: http://107.173.191.111/ghy77/winlogon.exe
URL Status:Offline
Host: 107.173.191.111
Date added:2021-11-24 18:28:04 UTC
Last online:2021-12-04 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-11-24 18:29:09 UTC to abuse{at}colocrossing[dot]com)
Takedown time:9 days, 9 hours, 20 minutes Bad (down since 2021-12-04 03:49:46 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-25n/aexe 869f1c084b45e3c4ba1e6b44dc00d48f2fd68e0c5d2dddd563c4ce10cd7c60c9n/a 
2021-11-25n/aexe f458904833c4f2e20b9dedbea23e7e1488b8decbc10c6fcddc6e977c58281d86n/a 
2021-11-24n/aexe f4ba4c7cfa06963a05eb720c098686c8296e799fcfe96c7f44ae1b9ef814c1daVirustotal results 35.29%Formbook