URLhaus Database

You are currently viewing the URLhaus database entry for http://107.175.212.108/offer/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2247150
URL: http://107.175.212.108/offer/winlogon.exe
URL Status:Offline
Host: 107.175.212.108
Date added:2022-06-22 06:53:05 UTC
Last online:2022-07-11 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-22 06:54:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:19 days, 13 hours, 2 minutes Bad (down since 2022-07-11 19:56:13 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-08n/aexe 1fb52fd8e565ad6737e96ed8256dcfde69bb7ad7b0d81f15317dc25e2dbfc8c7Virustotal results 24.64%Formbook
2022-07-06n/aexe 6327a304232cb119909f486a6e1e5c50ae078910c48e6d3d2f718a08629d688cn/a 
2022-07-05n/aexe e737f942ef43bb1073c6f3c27d6689483ef091f60d38297628e198a0637394cen/a
2022-07-04n/aexe 4088d3ecdad783f1ee1dadef3a0faf413b498acc7285d3eb643a05f7bd64fa8cVirustotal results 16.18% 
2022-06-29n/aexe 96f84105f7c2a8f0c6ad5b87bf6efd54ba63369674962c142266dbef81d4ce14Virustotal results 41.79% 
2022-06-26n/aexe 659e83e55702067d1a62f082238c752daf8b35e7eb66454cafb47b6618610009n/aFormbook
2022-06-22n/aexe 12073c53d3b3398029c8557892e33485943dfea94478a9192ed3c362de2a1a64n/aFormbook
2022-06-22n/aexe b359375e9ac1bbd90bcb60c5fc6834d8a12ee2f4aadb34a001bda42a1c93b228n/aFormbook