URLhaus Database

You are currently viewing the URLhaus database entry for http://103.29.0.182/kung/bin.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2832452
URL: http://103.29.0.182/kung/bin.exe
URL Status:Offline
Host: 103.29.0.182
Date added:2024-04-30 06:44:15 UTC
Last online:2024-05-25 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-04-30 06:45:13 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:24 days, 18 hours, 38 minutes Bad (down since 2024-05-25 01:23:48 UTC)
Tags:exe Formbook link opendir PureLogStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-12n/aexe 1af8a1e2275df2662b4aa66adcf7e95de567c5a56295c143c736c7b3ea83473dn/a 
2024-05-12n/aexe ed8d1e06b81c6023836e374f187e1239efb7d86dea07f8fd3a02f4ea8ad22d31n/a 
2024-05-01n/aexe c99a398e776b36bf0f1aa9559a4be2cd82d4fd260db169e5236d29fb27622a4aVirustotal results 29.58% Formbook
2024-04-30n/aexe 3911ca0a3ba01ed03c568bf9e8dba24af0a2d0c4cd05cc4d453d17729f2feaceVirustotal results 47.62%Formbook