URLhaus Database

You are currently viewing the URLhaus database entry for http://104.168.32.14/m/efx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2237727
URL: http://104.168.32.14/m/efx.exe
URL Status:Offline
Host: 104.168.32.14
Date added:2022-06-14 12:49:04 UTC
Last online:2022-06-16 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-14 12:50:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 17 hours, 18 minutes Poor (down since 2022-06-16 06:08:18 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-15n/aexe 4fbb7e8f2be8677246de09da661752a40ea6005336c5e3e4105a1db0af052357n/a Formbook
2022-06-14n/aexe 45b9f90bee542ccb1e839ba824246f94363e35610981b9620429beecfcedc66bn/aFormbook
2022-06-14n/aexe 3cebca22e511f35079c2a7a26b333d742d6906277f455c5e421a9fca01e5f1ean/a Formbook
2022-06-14n/aexe 3a9cec6acfa41d46ff27e276a87461a472946b831110b00682f76fc629db2c45n/aFormbook
2022-06-14n/aexe 8b02875426e9b8b7074487c959a5220399e4c965f5bac608d9a65b66f4d62c71n/aFormbook
2022-06-14n/aexe 3046a58999ef12bbe6472b373836767bf4e5fd15a50e14d26f7e344c033e61d3Virustotal results 44.12%Formbook