URLhaus Database

You are currently viewing the URLhaus database entry for http://95.214.27.254/getfile/winlog.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2709204
URL: http://95.214.27.254/getfile/winlog.exe
URL Status:Offline
Host: 95.214.27.254
Date added:2023-09-03 06:45:10 UTC
Last online:2023-09-11 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-03 06:46:06 UTC to abuse{at}delis[dot]one,abuse{at}des[dot]capital)
Takedown time:8 days, 6 hours, 3 minutes Bad (down since 2023-09-11 12:49:16 UTC)
Tags:exe LaplasClipper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-08n/aexe 203abb4fef06659cf437ca0d5c338b7e0ed1add2645361ba92ab5aab6e3a0e08n/a 
2023-09-06n/aexe bf1f92e316a65678c025d3a24241f825fe7c306e36a693f511f2d0461b32140bn/a
2023-09-05n/aexe e08378a18f28c838f8bba59d0b7d04b240b190678685bd6a8db039d45889e469n/a
2023-09-04n/aexe 11f52163f4d22333963f0bc9512c632e0763bd9f66e08171acfcc142c508e5d5n/a
2023-09-04n/aexe 44f76e0e8cc99d0387e0df11533ae8472ebecfb21142bc286e95b8fd99c45751n/a
2023-09-03n/aexe 589b49a8e56beb55dcdacec0cdc3e04949eaa678df53d720ba940c7193130344Virustotal results 57.75%LaplasClipper