URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.107.201/cc/loader4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2004815
URL: http://198.12.107.201/cc/loader4.exe
URL Status:Offline
Host: 198.12.107.201
Date added:2022-01-25 10:08:33 UTC
Last online:2022-02-28 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-25 10:29:52 UTC to support{at}vpsace[dot]com)
Takedown time:1 month, 3 days, 20 hours, 14 minutes Bad (down since 2022-02-28 06:44:49 UTC)
Tags:AgentTesla link exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-24n/aexe 720a9b41aa3fc632a07dc0fa3c376ea608898049e6bdb761010695331c0d0b34n/aLoki
2022-02-23n/aexe 4dd8aa04ac02dd1fb4aae41cb1160b968896f399612203ab56dfed1ee0bff6d6n/aAgentTesla
2022-02-16n/aexe cb645ce6e574b6ee14f603cca85eec21596945642b578e2290ed9924ee5b3f24n/aLoki
2022-02-16n/aexe 5ab3f9c064ba8fe1118806854873fbb05d7e2c01b5a6a8f70ecb43e8c0ba793an/aAgentTesla
2022-02-10n/aexe d695e70ec9d4e89c90dc0658449fd2662dac8dacbf91537b9ca8c1afaa20f3e6n/aAgentTesla
2022-02-10n/aexe 22099fbafc3dda95912c51aa0c313826f21e2fe84ef51453c649f66ab29c6916Virustotal results 45.45%Formbook
2022-02-09n/aexe 820b1216485962fa3501dc8bd02a76bdb821fd7b6ffab858c4ebe135c4246090n/aFormbook
2022-02-07n/aexe 4f6383c6ae7c88ff6ab189dc208b3f159d87b824011a697f438a218fc07fa3bbn/aAgentTesla
2022-02-07n/aexe 60babc2401d599558b2eb901ab162c87ca59bda068bfee2561dfb1ec4aba0b2an/aLoki
2022-02-02n/aexe 47ce85235c5492b7a415ad34c4086d1ba2f0407ec00123efb677cc3737c89b21n/a 
2022-01-30n/aexe 89a5384b284e44d23891f6b22590f0194c4ac0b2b6507bb51fa678ede6d6069an/aFormbook
2022-01-26n/aexe ffebbdfbf43481f261924e72b9c3acb4b503d41549ab926015159af4d1f7f1fcn/aFormbook
2022-01-25n/aexe a58fa4c9cd9960a9b7c8fbab4942b3d1f28035ce37b68b4835afa9e728cbdc0an/aFormbook