URLhaus Database

You are currently viewing the URLhaus database entry for http://195.178.120.118/loader/winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2412747
URL: http://195.178.120.118/loader/winlogon.exe
URL Status:Offline
Host: 195.178.120.118
Date added:2022-11-15 11:31:05 UTC
Last online:2022-12-29 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-15 11:32:09 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:1 month, 13 days, 12 hours, 47 minutes Bad (down since 2022-12-29 00:20:01 UTC)
Tags:exe Formbook link GuLoader link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-23n/aexe 5f8e9ae71eba679754663351ebaf0668bee3ef9ac7c95ad0261fe97bc3424753n/aFormbook
2022-11-21n/aexe 4123e34ccee4506fdb642e75de44d8d91ce349dc286e5bc1df9ced77f2aac2c3n/aFormbook
2022-11-21n/aexe d40a4b8e0d7364607fdb220dd109b6272026193eb794206fc4ed2ae86cd8588cn/aFormbook
2022-11-21n/aexe e549a60b2413738da0eab6717d8d567e47b208335420a2ea8ef3bf276ac25ab3n/aFormbook
2022-11-18n/aexe 652bc1a671a93da40aa71662ab1101cf509a792fba2acd21a8d026988ee00d03n/aFormbook
2022-11-18n/aexe 61a3bd64ed25ff3b8481b54b9678ed5518bd53245fa43c222c6fec42b26e05cbn/aFormbook
2022-11-18n/aexe 5c69938a04aa7ca2d20e4fa560acc5cd7cc6067c74e32ea771528e6e880f7491n/aFormbook
2022-11-17n/aexe ae485bf47cc4d6f61e9f6ffdfa764fd02f98f537a9ea663cf29cfdaa50979341n/a Formbook
2022-11-16n/aexe 0291db4aefb6f981b515729c8e5cc8765af976aa31ae1d0d985b17ba66d29f0cn/aFormbook
2022-11-15n/aexe ff2c1d0bdc27e3137837afac350c6e433e86d4523f32555b3b59de1aa0981c53Virustotal results 5.63%GuLoader