URLhaus Database

You are currently viewing the URLhaus database entry for http://107.173.191.79/draft/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1948988
URL: http://107.173.191.79/draft/winlogon.exe
URL Status:Offline
Host: 107.173.191.79
Date added:2022-01-04 16:35:06 UTC
Last online:2022-01-20 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-04 16:38:34 UTC to chris{at}mohawk-host[dot]com)
Takedown time:15 days, 14 hours, 40 minutes Bad (down since 2022-01-20 07:18:44 UTC)
Tags:AveMariaRAT link exe Formbook link opendir rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20n/aexe 325161475d78040b7747dede24421e11ccd705849e73752487fb51d9c0b5cda8Virustotal results 35.29% 
2022-01-17n/aexe 10d7529f4fbf887796b8d6110dcf18bc77f9225a8be593235be080caf10b7d74n/a 
2022-01-17n/aexe a1d8420052bbdcaf3d318427bfe57edf5cc330fb14aaa5f4a597fac220c2a6den/aFormbook
2022-01-14n/aexe 0581160998be30f79bd9a0925a01b0ebc4cb94265dfa7f8da1e2839bf0f1e426Virustotal results 1.49% 
2022-01-14n/aexe d7dc43fd6d64d75b9cf206ee3960055bc4f5b5db2ad0e7902eb2cef32c7d9e8cn/a 
2022-01-13n/aexe a15402c5f869a1c02421742c27dd71c2448bb037d391a6bf130be06b2f976e2fn/aFormbook
2022-01-13n/aexe 6846492babd6809fcbf6d1a30ebd47db29061bc23237069ff85a86b406b1abb0n/aFormbook
2022-01-12n/aexe 0a01299cae838e8920ce78f846e94890d3a08619316aacfe34f9deb0b364d69cn/a Formbook
2022-01-11n/aexe 4f64511b423d79682dfad8f6b516516d32e801f0031f07b7e3c6c19798a64b95n/aFormbook
2022-01-11n/aexe c5f98ce0715f0bd5d20c6a9c94502b01877f83859aebe53f62bc3d278eb05678Virustotal results 26.47% 
2022-01-07n/aexe 15f9ae45222e5eb82ac39303b8f9b852399bbf3ea54c3f7ff7d04e76756bc43fn/aFormbook
2022-01-04n/aexe 55fc10ee991ca372843138e21109e0941cb42f5ae70f40a9442aed3bf98f2642Virustotal results 39.13%AveMariaRAT