URLhaus Database

You are currently viewing the URLhaus database entry for http://44.203.122.41/Archevod_XWorm.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712126
URL: http://44.203.122.41/Archevod_XWorm.exe
URL Status:Offline
Host: 44.203.122.41
Date added:2023-09-17 12:44:10 UTC
Last online:2024-02-28 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: ThreatShikari
Abuse complaint sent (?): Yes (2023-09-17 12:45:07 UTC to abuse{at}amazonaws[dot]com)
Takedown time:5 months, 14 days, 2 hours, 31 minutes Bad (down since 2024-02-28 15:16:56 UTC)
Tags:AsyncRAT link Formbook link xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-07n/aexe 4bb0daf6ad46380eb905da9f586d108f9a9e7bd83c31d7903824ebe3abd65fb0Virustotal results 71.62%AsyncRAT
2023-12-02n/aexe 0893cfe208c34030552ccd250f5e185d42423f4ebb5311a13f68e5bd96a1cad7n/aAsyncRAT
2023-11-24n/aexe fa5a74ef1355ddd1d5984b84d52d7aa0727e11e40a89ca3a2bbf4594eea57730n/a AsyncRAT
2023-11-22n/aexe 7c408a938968a84928bb5d9da2be3a54e39cd8f8930e104ba13f1871f0b168fan/a AsyncRAT
2023-09-29n/aexe 50a3d3508c4b826b4e36678dd91b374c339b0c57a89a31cd3e9f5a4441772dc0n/a XWorm
2023-09-29n/aexe dd38b89961f68c5aa0ca5d2deca8f910bac2478927f5a8d85c808f0a6902d433Virustotal results 68.06% XWorm
2023-09-25n/aexe 9b6eecaa9a316a2f4363b98691c52d775ba9c641fc13e9a2d0cde7ae725dd3b0n/a Formbook
2023-09-17n/aexe bf9c7574e3ca23a96e317b42385aee11a982ab20649a6954d507e9c76b4044b5Virustotal results 76.81% Formbook