URLhaus Database

You are currently viewing the URLhaus database entry for http://107.173.191.82/draft/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1995426
URL: http://107.173.191.82/draft/winlogon.exe
URL Status:Offline
Host: 107.173.191.82
Date added:2022-01-21 11:04:06 UTC
Last online:2022-03-23 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-21 11:07:32 UTC to chris{at}mohawk-host[dot]com)
Takedown time:2 months, 0 days, 17 hours, 21 minutes Bad (down since 2022-03-23 04:29:25 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-31n/aexe 1b77ac028b4a0c0c9262c945bb5480ec1bbfa3503b547fd11d34735d87245548n/aFormbook
2022-01-31n/aexe a1bf6120b566e76d3df3b722c1a517fe69b74e670d70bde100c4cf04e3ee947en/aFormbook
2022-01-28n/aexe f1d8d7b78bd6e53b4cfa63bc4f03ec0c9d7baad72c0e697993fd3354df4ab0fbn/a 
2022-01-27n/aexe 0784e25928771037529d996131314b35bef0b765c64c6258a634825d2181a8ebn/a 
2022-01-26n/aexe 41e0f6ad541e5253c451b3d51976df257813e85c443ab1b863b3acf6c078b38cn/aFormbook
2022-01-25n/aexe d5602c843c62b0a5ec27f595ca64c47ece77e57ad062c7124a8c24d536c757fdn/a 
2022-01-25n/aexe 11e5030403c99dfa27a1c41a8a3abf2408324166735b081a7db038c9a3ec357dn/aFormbook
2022-01-25n/aexe d2c9827978276132cc38a69bb87dbf7ab682d04d194271f460f3bd14d76f9c2cn/a 
2022-01-25n/aexe 0d42799a7602de1d76ef3b39ceff5075b95dd1e3891332987d525a07ef5c5f0fn/aFormbook
2022-01-25n/aexe a632daf4953367bf3024b3e84d13b5beb03d77719cca10b155355e474b3173e3n/aFormbook
2022-01-24n/aexe cad3a123656beb7ff1cc7f5549991c0d8e49e054802faf27383d19c0d5bf80f2n/a 
2022-01-24n/aexe 28a107f37e75bafd9fd49ac3ed8745d676d04d2bd5bfea8f926f04a2f393cd51n/a 
2022-01-23n/aexe 0581160998be30f79bd9a0925a01b0ebc4cb94265dfa7f8da1e2839bf0f1e426Virustotal results 1.52% 
2022-01-21n/aexe cfdf477d386cab73129ac775a953d693466176d4d4854d06d580125a8f20f9e6n/aFormbook