URLhaus Database

You are currently viewing the URLhaus database entry for http://77.247.110.140/trump/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2070349
URL: http://77.247.110.140/trump/winlogon.exe
URL Status:Offline
Host: 77.247.110.140
Date added:2022-03-02 07:51:05 UTC
Last online:2022-03-15 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-02 07:52:09 UTC to report{at}peenq[dot]nl)
Takedown time:13 days, 1 hours, 1 minutes Bad (down since 2022-03-15 08:53:32 UTC)
Tags:AveMariaRAT link exe Formbook link opendir rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-14n/aexe c8781b8dca56fa093b3df95c16360b2dc381eadb10b4f9055e11b39f34284749n/aFormbook
2022-03-14n/aexe 9b989810b625c75d2d669edbb692f4bfd55684f71f3c082e80609ee68e4fe06fn/aFormbook
2022-03-06n/aexe 55f2a165cf0284c07d8946b8b5b461adf801fd1dc5d84445d24cd2960cd46815n/aFormbook
2022-03-03n/aexe c7ceb2adec0ec0d5d01cbbc2753f0c2ddfc149c2e4daa47a519f44604ea5e557n/aFormbook
2022-03-02n/aexe 757cd8cf8e9d17c61a1f5308d75ff5eae936d15f25fac859f8731b0e7030d4adn/aFormbook