URLhaus Database

You are currently viewing the URLhaus database entry for http://3.111.196.139/122am/fodhelper.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3129418
URL: http://3.111.196.139/122am/fodhelper.exe
URL Status:Offline
Host: 3.111.196.139
Date added:2024-08-26 12:55:16 UTC
Last online:2024-08-30 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: SynapticShaam
Abuse complaint sent (?): Yes (2024-08-26 12:56:10 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 days, 1 hours, 31 minutes Bad (down since 2024-08-30 14:27:22 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-28n/aexe 821475247fd0e03841c0d5dd9f0189bc6afb8932a8915a802e102659ca55fd11Virustotal results 21.33% Formbook
2024-08-28n/aexe c8cf55959a83b4996ae05b403484224cdf8f5af0272e3e243be0381ce37e2512Virustotal results 20.27% Formbook
2024-08-27n/aexe b60d2cbc3ae816f68798909803d71c10ecc6c970894097b4ea20038e508eb0b7Virustotal results 24.66% 
2024-08-26n/aexe 1cc966797759658cf1d26bf74c88c5d41ee52f0461676de7877060a03ed7e17cVirustotal results 22.67% Formbook
2024-08-26n/aexe 2c4d8b09e22c2808778be4086e8482dddeeea90ec1954ba3fbec284585b6f581Virustotal results 37.33% Formbook