URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.119.75/cloudprotect/winlog.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2202457
URL: http://172.245.119.75/cloudprotect/winlog.exe
URL Status:Offline
Host: 172.245.119.75
Date added:2022-05-19 13:51:06 UTC
Last online:2022-06-03 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-05-19 13:52:14 UTC to support{at}vpsace[dot]com)
Takedown time:15 days, 9 hours, 21 minutes Bad (down since 2022-06-03 23:13:59 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-23n/aexe 5dc6a22527eea05f65ad1dad961d5a80019165c43c1c492cf3449f4a4a909ce2n/aLoki
2022-05-23n/aexe cb8eea2a6f0eccf50dd219c7aefa8c0827a9ea5fb929a6fd4d98741f9d14be2fn/a Loki
2022-05-20n/aexe 1bebac82bd6764612962f1a3daed34a11df24d659cda7fc8ceabcaa3a18e5cf9n/aLoki
2022-05-19n/aexe e573934b8351e4f56c1b5d4e587ae7c48081961f2cb9e3a5f4245230a216560bn/aLoki