URLhaus Database

You are currently viewing the URLhaus database entry for http://45.88.67.187/new/new.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2512463
URL: http://45.88.67.187/new/new.exe
URL Status:Offline
Host: 45.88.67.187
Date added:2023-01-19 14:41:11 UTC
Last online:2023-02-11 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-19 14:42:05 UTC to abuse{at}des[dot]capital)
Takedown time:22 days, 17 hours, 23 minutes Bad (down since 2023-02-11 08:05:58 UTC)
Tags:bazaloader link exe Formbook link opendir PureCrypter VectorStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-08n/aexe e4ae7f58c9e924cc6dac0208b5f6438e15174d978d013e0125f814af1509afb7n/aFormbook
2023-02-06n/aexe 62931fe87c3452571f8bc4470b8115e18395e95d4c60255614e5eb51fed8f7c9n/aVectorStealer
2023-02-02n/aexe 8c86c2c68e14eef2ac6a63da35633b309ef75e7f818a6bf935e56471ed5dae53n/aFormbook
2023-02-02n/aexe 65f11a6c107a0d4f5c87193d2677b57abb3549f0342904c6248e7e61b7ecafe8Virustotal results 34.78%Formbook
2023-01-30n/aexe edc3a7a85b4c116fe3b5806dd71c08fa907ea41cd57c43abf0494135eac0595fn/aPureCrypter
2023-01-30n/aexe 58b233a73b4f72cfba99e0ea154ddf515b5e80f9945984b1945ad87e7f4d2b1bVirustotal results 47.14% 
2023-01-24n/aexe 4a9eb160df466482bcd1df92ad97471321e4465e5e448821858506704edc11een/aFormbook
2023-01-24n/aexe 341cb4515476007153b7f17212f5e4476852837a031efedd5a4adea723c0bcbeVirustotal results 0.00% BazaLoader
2023-01-19n/aexe 50268da94205b374b7b1344a8ae09105e3732dd026350b7418d750a2d4dca7e9Virustotal results 41.43%Formbook