URLhaus Database

You are currently viewing the URLhaus database entry for http://107.174.138.132/vv/loader1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1983092
URL: http://107.174.138.132/vv/loader1.exe
URL Status:Offline
Host: 107.174.138.132
Date added:2022-01-17 07:51:05 UTC
Last online:2022-02-17 05:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-17 07:52:09 UTC to support{at}vpsace[dot]com)
Takedown time:1 month, 0 days, 22 hours, 0 minutes Bad (down since 2022-02-17 05:52:23 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21n/aexe cfd1a77378decd68cd7a59307b77b93247bdd91e00de5111ecae6b5658c8665fVirustotal results 38.81%Formbook
2022-01-20n/aexe 15c23eaba1a9b964fb6a755eeaf4ab00b8fa6d27f0f2a353b4bcd5a05f7e12e8n/a 
2022-01-18n/aexe a9dd9bda70b16a68d8f55e09a1f9bc5d29b49ca060d5642ac9057ab50968f262n/aFormbook
2022-01-17n/aexe 5068b78eb3bc654def466f25584df4410b45e5b99ebebd2e0b76086f1052ded1Virustotal results 30.88%Loki