URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/MmOM6DIK7db78fz.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3597799
URL: http://213.209.150.18/MmOM6DIK7db78fz.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-08-06 20:48:07 UTC
Last online:2025-09-15 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-06 20:49:09 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 9 days, 19 hours, 19 minutes Bad (down since 2025-09-15 16:08:45 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-08MmOM6DIK7db78fz.exeexe d61d38c490cbeb69dc98be97f33cf269fa4125891a837b02ca4b54704a05879fn/aFormbook
2025-08-07MmOM6DIK7db78fz.exeexe 9f65ef6f241d6501f4a2f4f18fa0472c68a5945c70f4cea2737b06ecdfdaf879n/a Formbook
2025-08-07MmOM6DIK7db78fz.exeexe 537abcac388bf90b8a8e7810fadd4f747626d742ff4859af18806320cc28e437Virustotal results 37.50% Formbook
2025-08-06MmOM6DIK7db78fz.exeexe 5fd14899e5c4f9446e6889bf93319de3cfa25265af9458397759a6083e27fc65n/aFormbook