URLhaus Database

You are currently viewing the URLhaus database entry for http://107.173.191.75/dodge/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1833497
URL: http://107.173.191.75/dodge/winlogon.exe
URL Status:Offline
Host: 107.173.191.75
Date added:2021-11-29 19:52:07 UTC
Last online:2022-01-13 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-12-22 10:57:33 UTC to chris{at}mohawk-host[dot]com)
Takedown time:1 month, 28 days, 9 hours, 24 minutes Bad (down since 2022-01-27 05:17:55 UTC)
Tags:AveMariaRAT link exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-07n/aexe ddae9e103982ab3a95b3095094152dca4f4b838dadc4c6128032b8e78f4d2059n/aFormbook
2021-12-07n/aexe 72fa6db7a26f706a401ec08755e29dd21034f7018e784be28b42df9001c2c9c9n/aFormbook
2021-12-07n/aexe e53117bb9ee3d0c9bfd3d94758b9d54c824776bc594549801bcae621962590fdn/aAveMariaRAT
2021-12-06n/aexe 8ddb1b007d499a165554e933dcfb0ce8a7ced3506f2609c2a5225c64755bb69an/aFormbook
2021-12-02n/aexe 50901c9bdf963127a05847c8c0a1d71d8c02310c491a159cf87a1e888ceab348n/a 
2021-12-01n/aexe 1e1f3aa6446fe8b19f1ddc52e9cf13aaaf7adb38af4a365caee4df0b746e9b2dn/a 
2021-11-30n/aexe 1882f85508e07e15d4829da1996263d19e2a06ddb3e70a3852379835743db2b0n/a 
2021-11-29n/aexe 33dd7290dd0dd02b34235fda39f1d72c369e01aa13854e0c792c048302f2f094Virustotal results 31.34%Formbook