URLhaus Database

You are currently viewing the URLhaus database entry for http://107.174.138.132/vv/loader4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1983091
URL: http://107.174.138.132/vv/loader4.exe
URL Status:Offline
Host: 107.174.138.132
Date added:2022-01-17 07:51:05 UTC
Last online:2022-02-17 06:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-17 07:52:09 UTC to support{at}vpsace[dot]com)
Takedown time:1 month, 0 days, 23 hours, 3 minutes Bad (down since 2022-02-17 06:56:01 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21n/aexe c7eeea84c68c73b96a2bc816b9738ca8c9c2abe93f7705ec07f8d1205422d86eVirustotal results 47.76%Formbook
2022-01-20n/aexe c0904a36e97e50225bc8ab11f7a9c588ebc758b1dc624d39d94da1f5268b847en/aFormbook
2022-01-18n/aexe 38ff81c0547d423ae07f234ec45351dd976300cc5197274b6be8dad0b89ec61en/aFormbook
2022-01-17n/aexe 34c73b45a213c0818ff15da43291aae7119069dbb7ecbc48bdfb04f9c7afb2a6Virustotal results 33.82%Loki