URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.228.34/new/new.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2251294
URL: http://192.227.228.34/new/new.exe
URL Status:Offline
Host: 192.227.228.34
Date added:2022-06-27 15:28:09 UTC
Last online:2022-07-28 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-27 15:29:06 UTC to support{at}vpsace[dot]com)
Takedown time:1 month, 0 days, 13 hours, 56 minutes Bad (down since 2022-07-28 05:25:39 UTC)
Tags:bazaloader link exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-14n/aexe 341cb4515476007153b7f17212f5e4476852837a031efedd5a4adea723c0bcbeVirustotal results 1.45% BazaLoader
2022-07-06n/aexe bf694c0a4856be7c6e88f8d018a2d3223b740f060e9c0f8da51df710c895860an/aFormbook
2022-07-06n/aexe dd9fbbd174254c6f01640f1e9af92ff2313489a4782d1b14b14be8040e3dfd99n/a 
2022-07-04n/aexe bab64eb4ecf7a8b078589c183dd8ece844bd0204e8088433548fc029cc2f5ae0n/a 
2022-07-04n/aexe 16bb73c91093fa255cc5c2ff552fb87f8847eaaf21cdf517971b9c53af4c45c4Virustotal results 34.78% 
2022-06-27n/aexe 81398fcf0e9612b507cbdf18df673c828d8e08bd8a6abbfcf00261fe84e0bb8dn/aFormbook