URLhaus Database

You are currently viewing the URLhaus database entry for http://104.168.32.14/u/lux.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2237707
URL: http://104.168.32.14/u/lux.exe
URL Status:Offline
Host: 104.168.32.14
Date added:2022-06-14 12:07:04 UTC
Last online:2022-06-17 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-14 12:08:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 20 hours, 42 minutes Poor (down since 2022-06-17 08:50:21 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-15n/aexe 7b008de94024ab843b049c1b90502b0515fb5496801e2277e83efd21fa0624b2n/aFormbook
2022-06-14n/aexe 45b9f90bee542ccb1e839ba824246f94363e35610981b9620429beecfcedc66bn/aFormbook
2022-06-14n/aexe a826c8bf4c09979bf9b0662ffa94623f2ea74c1dbb57b1e95d16a708a35c3095n/a 
2022-06-14n/aexe faab64c137398fa8f253f500bdaf7445367cbcbdf35e833508086cb89d9ee0den/a Formbook
2022-06-14n/aexe 8b02875426e9b8b7074487c959a5220399e4c965f5bac608d9a65b66f4d62c71Virustotal results 22.39%Formbook
2022-06-14n/aexe 66e116c38693b688041b05db22425b15f5a3a854826eb2fda04cc2b338bb5ab3n/a 
2022-06-14n/aexe b0cbfc5f55798bee84a760d2a857c6c52da5f0d69e8076d67952793d47d8a59bVirustotal results 45.59%Formbook