URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.193.171/950/Chromium.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2704672
URL: http://192.3.193.171/950/Chromium.exe
URL Status:Offline
Host: 192.3.193.171
Date added:2023-08-15 11:59:04 UTC
Last online:2023-08-18 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-15 12:00:12 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 18 hours, 20 minutes Poor (down since 2023-08-18 06:21:08 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-17n/aexe 3fc5cc5b1cbf56ae33c6bc87d39c58a0e034f21ddb7c999a7d505b0044b2e85fn/aFormbook
2023-08-16n/aexe 2b33fca6ad1c4aeccf99eb4fd10ebdd20a00e2889769a1cf34f18d905504d082n/aFormbook
2023-08-16n/aexe 328dcb82382c5fb34a7f5a4892cfbdeec6e990551f3ebdcdcfec98e70b0b0327n/a Formbook
2023-08-16n/aexe 23a0504b8ac3cb1b913d15da848866607a4c617b8bbb5555a71962a6cffadeedVirustotal results 43.28% Formbook
2023-08-15n/aexe 1a4a833905ed2b06f990054eee77c7f92d536d52797c6a18de6d1358e25e8e03Virustotal results 45.07%Formbook