URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.212.228/kobo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2069331
URL: http://198.23.212.228/kobo.exe
URL Status:Offline
Host: 198.23.212.228
Date added:2022-03-01 19:15:05 UTC
Last online:2022-03-19 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-03-01 19:16:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:17 days, 9 hours, 52 minutes Bad (down since 2022-03-19 05:08:16 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-09n/aexe 87beb68823a2b2b936e83e4b24744ec8afb0506382dd0c1b613580b02230952aVirustotal results 19.70% 
2022-03-02n/aexe 65f1f8cdc7b79ad8b44eb1104908dfc2354c50e5550796916d3180fdb15af1d5n/a 
2022-03-01n/aexe 6394de1149bac235402b7a6453331c0585bfcd54d2a31ce7e44b42fb24caf615Virustotal results 50.70%Formbook