URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.73.137/dd/loader2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2188449
URL: http://107.172.73.137/dd/loader2.exe
URL Status:Offline
Host: 107.172.73.137
Date added:2022-05-10 12:55:04 UTC
Last online:2022-06-22 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-10 12:56:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 13 days, 1 hours, 52 minutes Bad (down since 2022-06-22 14:48:12 UTC)
Tags:32 exe Formbook link Loki link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-20n/aexe b5d0a357f90964778e29fb229eab1f456ad7087253098426ccaf989cea4bff8fn/a RedLineStealer
2022-06-10n/aexe d7300261799ca558fe3d08dbe2838388e9157acf98f74e1fc34019480081b3afn/a RedLineStealer
2022-06-08n/aexe c2df32fd3ca2f42e8361af3717e1eab54d908809d685b39c403e492e6a5125b9n/a RedLineStealer
2022-06-07n/aexe 21c7e9b8ab9e92821928a6bb1860b31a53b2d4da0dcdb340388ee7f177d2b964n/aRedLineStealer
2022-06-01n/aexe b9e0d6a9c945576fb24507299b953652f3781cfde1ecaa1808e17ef315a50d57n/aLoki
2022-05-18n/aexe 5e0b3793ea67f580aa658ab4629f7a4f4f9e307083c4ac4b6604a959d204b856Virustotal results 28.99%Formbook
2022-05-16n/aexe 52a539866fa6472c9c5367c5318e2cd9c5acb140701f2ca97d5869ca47b88457n/aLoki
2022-05-10n/aexe 9c31d9a430e6dbe6d92835442a8371d277ae07b8bac0190ce3b4a2d22e59352cVirustotal results 42.03%Loki