URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.156.251/42/wins.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2680688
URL: http://198.23.156.251/42/wins.exe
URL Status:Offline
Host: 198.23.156.251
Date added:2023-07-11 13:45:09 UTC
Last online:2023-07-13 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-11 13:46:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 19 hours, 45 minutes Poor (down since 2023-07-13 09:32:01 UTC)
Tags:DarkCloud exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-11n/aexe 36d0c8e58fabe82307b7b36444e075f5dccd1a57e7b73551d335f76645b11274n/aDarkCloud
2023-07-11n/aexe 2150f0caeac604ff6b396c3cf863dab727dca9b3c996a7a2aa7e5ea78d0bdae3Virustotal results 42.25%DarkCloud