URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.107.201/cc/loader1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2004811
URL: http://198.12.107.201/cc/loader1.exe
URL Status:Offline
Host: 198.12.107.201
Date added:2022-01-25 10:08:07 UTC
Last online:2022-02-28 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-25 10:10:33 UTC to support{at}vpsace[dot]com)
Takedown time:1 month, 3 days, 20 hours, 29 minutes Bad (down since 2022-02-28 06:40:00 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-23n/aexe 0cd9de7fee952994367b5dbdf4593be74d0926b262e6ed8bd45d0205923ffc07n/aLoki
2022-02-21n/aexe a2e6c9d50d2fd9c7c7401f63d7bfa0ab83d781e2d91737d2506cebf247c318d5n/aLoki
2022-02-17n/aexe cb645ce6e574b6ee14f603cca85eec21596945642b578e2290ed9924ee5b3f24Virustotal results 41.43%Loki
2022-02-14n/aexe 4d854fee4f2e2a7b2afb2c13b28207f5388b095d0f7f053b90e03cf5873904e9n/aFormbook
2022-02-10n/aexe 28d6ebb9c7ae67a73c11392f36e3b55b56c4709f9abe7c70ab02a9deb0e6de44n/aLoki
2022-02-10n/aexe ce6b42f991a1ce90598cbf00ed844cfd5bcf6acb51302b8c9b2885fe29be3836n/aLoki
2022-02-09n/aexe af7abd08a5752f55f59e38b2bd9568943ada7d2b23ddc3324b735beebd8846cen/aFormbook
2022-02-07n/aexe 703f4546b4adc3e685275a9840bafac150717c3259f629f6bf9bd8e5d191ad46n/aFormbook
2022-02-02n/aexe 34f5584252c0001e14a3edfc7a29c5828b14d3af6ab2fdac73d4cf4f806600dfn/a Formbook
2022-02-01n/aexe 0da36b7f7e4b44b640ab5769532fdd7599032ca2b1d6b57807ba48ad1fa76780n/aFormbook
2022-01-30n/aexe 5ed4b0af136119c2bc78ca0cc3e0b58f77fbe72e9c7218d7c64f3caa2e5eda5en/aFormbook
2022-01-26n/aexe db751d20fa3ae449c73167571724c5dc773161f33e095ef74fa23ca66cfa8129n/a 
2022-01-25n/aexe 75362f20dab8d57db3ade6427e647b0bc01d8345ccfa9781d5778877f04f7fb5Virustotal results 58.21%Formbook