URLhaus Database

You are currently viewing the URLhaus database entry for http://185.216.71.172/bobo/twt.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2410384
URL: http://185.216.71.172/bobo/twt.exe
URL Status:Offline
Host: 185.216.71.172
Date added:2022-11-14 07:17:04 UTC
Last online:2022-12-11 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-14 07:18:08 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:26 days, 20 hours, 2 minutes Bad (down since 2022-12-11 03:20:09 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-22n/aexe 05d5b7b0b909b0921c90487f5e91cda6dfa9390432616d892bf7aed24f24104aVirustotal results 37.68%Loki
2022-11-22n/aexe bbf78f254ad97ff0967e58b1b691998401d292e813cb397721ca526266786e7fn/aLoki
2022-11-22n/aexe 8abcb72b5f7d20b160034cbc6ae854e55d52c2dc68c0b7334a60b71ebd884177Virustotal results 40.58%Loki
2022-11-14n/aexe 5b51a7e451c70c0271f21acf38747c5af235c18394585c4470f127c343b6ff8cVirustotal results 43.06%Loki