URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.207.51/tbag/LoaderX.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2235999
URL: http://198.23.207.51/tbag/LoaderX.exe
URL Status:Offline
Host: 198.23.207.51
Date added:2022-06-13 06:41:10 UTC
Last online:2022-06-23 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-13 06:42:08 UTC to abuse{at}colocrossing[dot]com)
Takedown time:9 days, 21 hours, 36 minutes Bad (down since 2022-06-23 04:18:55 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-14n/aexe 38d9e46ffe8d5d1405ac99da1a744e591bc93232a51a89add6d10c00d0957710n/aFormbook
2022-06-14n/aexe c578a70b3fe2f788f59898f782658c68b0d7e2ebe1ac30de156b1e65c270c061n/aFormbook
2022-06-13n/aexe 482beb0818b4fb36d99de34bd14974c236009b5dea1b8a3fad616da83044d025n/aFormbook
2022-06-13n/aexe 4fac64123dd9801541374d8d3bb647ed3f4378890841a7002ea48f3b14ea3872n/aFormbook