URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.76.193/pond/fox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2108904
URL: http://107.172.76.193/pond/fox.exe
URL Status:Offline
Host: 107.172.76.193
Date added:2022-03-21 09:15:05 UTC
Last online:2022-04-15 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-21 09:16:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:24 days, 18 hours, 24 minutes Bad (down since 2022-04-15 03:41:05 UTC)
Tags:AgentTesla link exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-11n/aexe 54a2f208d30012237286d747e0f9c5e9d85fc5a101ad24900b569e0ec341e8c5n/aFormbook
2022-04-06n/aexe 3b14b04160d49bdd074d3d571992ed5333b8292a3c0f8f58988c606bd91408f9n/a
2022-04-05n/aexe 9e19fdd001c86c5fc90e6e376f9b3240ab21355a2f24728b81ae274b26f88437n/a 
2022-04-05n/aexe c550d15f0fea44b269ad7e9fdff3843a225a2b7d2a888d496a81058233bbfa9an/a Formbook
2022-04-04n/aexe f469b5c967ff28b96444a48b6769ccde102417de9d59df1878bfe486ade890ddn/aFormbook
2022-03-31n/aexe b4fa1ae3b195f78ce6c5b98684a0937910914de894f750ecd8e0088820d18878n/a
2022-03-31n/aexe e654eb888cf345f65b8363a808a86111d1c0bfeee51a78b0d0c756a7f3bd4c0cVirustotal results 33.33%AgentTesla
2022-03-30n/aexe 6cdd6c36d145369a75d707b389376e1c4854c927c6ba2635c59600e92bb7d050n/a Formbook
2022-03-29n/aexe 62b522aefc576e200d589cfcdc1487e68f6a17cc6eae30a705ccbae3964070e2n/a 
2022-03-29n/aexe ba347c1008ade9d22ce86ffc99ad1b8d8bb3fe4d392d911e8c4c2f2a11c98f13n/aFormbook
2022-03-29n/aexe e789763966dffd326114e10b489f2a3b981ccd11f189028704dbbd9a10d33823n/aFormbook
2022-03-28n/aexe 290a46cb558e5a98e28e74d3da5264d41bf2c9a6f20bf13a34c76037413b84f6n/aFormbook
2022-03-24n/aexe 1369b204f4383d9939cf856fb14e9072ccac3234a285fd905c9bec822893121cn/a AgentTesla
2022-03-23n/aexe f31986eaab55c34385bdb3fa8530663440f717656a7e3b20561fc42d40c96746n/a 
2022-03-22n/aexe 145f840479b9baa3431886abf20b30820f2cc5fe427c0d14390818c7e38ad3cdn/a Formbook
2022-03-21n/aexe 1c67eb0637866fef3d52fa28ffaedb9869c7f92560a58db83f1d0bc27cc8df1fVirustotal results 36.23%Formbook