URLhaus Database

You are currently viewing the URLhaus database entry for http://212.192.246.198/order/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2197275
URL: http://212.192.246.198/order/winlogon.exe
URL Status:Offline
Host: 212.192.246.198
Date added:2022-05-16 12:04:04 UTC
Last online:2022-05-24 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-05-16 12:05:07 UTC to abuse{at}des[dot]capital)
Takedown time:7 days, 12 hours, 54 minutes Bad (down since 2022-05-24 00:59:43 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-17n/aexe dfa8f64716c1395f7655779359a76299e1e80e2d205c9b3ae204e563a6d39574n/a 
2022-05-17n/aexe 78226a336cf7f2c786f893ef5282a9215e911a7c6a6a7d431df561f559e1e1e7n/a 
2022-05-17n/aexe 783ded110f2bf72b3d5acbc29d22177e9e963f08cd11ac2801a838adaa620a58n/a 
2022-05-17n/aexe 876516ba770a2af349bd5559444aedae5bc4a91199e71c922698cd358a3aa8d1n/a 
2022-05-16n/aexe 82f980f9c0e7dffaff12f27756975e9e551f2ffd432d6854d37106adb27ec0aen/aFormbook