URLhaus Database

You are currently viewing the URLhaus database entry for http://109.169.89.117/new/sel/sel.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:84095
URL: http://109.169.89.117/new/sel/sel.exe
URL Status:Offline
Host: 109.169.89.117
Date added:2018-11-23 11:12:03 UTC
Last online:2018-12-25 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: cocaman
Abuse complaint sent (?): Yes (2018-11-23 11:12:04 UTC to abuse{at}rapidswitch[dot]com)
Takedown time:1 month, 1 days, 19 hours, 7 minutes Bad (down since 2018-12-25 06:19:20 UTC)
Tags:Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-11n/aexe 6a3f5482c2bb9d04512197f6ae4178ec5d401724d1fc0773837706378c409ccen/a Formbook
2018-12-10n/aexe 0993eee8eef5efee387f7940d2682ded81d883e59a529a531985812e50e43d3bVirustotal results 4.29%
2018-12-10n/aexe 81de431987304676134138705fc1c21188ad7f27edf6b77a6551aa693194485eVirustotal results 0.00% 
2018-12-09n/aexe e5cf5aa87e3d363fb8b36d16f7d8373fff25cce3f8e3f39639fa2ec43fd1aad1n/a Formbook
2018-12-07n/aexe f2952a6b832f9d1e1f31a00bfacbe6ee9144d6951429866b4a2fbb283953daafn/a Formbook
2018-12-04n/aexe 02d51c1f006c3b8309e0bc607f896f991947282541a0de41afabb4c0de095858Virustotal results 40.58% 
2018-11-30n/aexe f92291984ec15b81a6940b5fc87557977800e5edbd4c17c175097d27eba1d549Virustotal results 58.57% 
2018-11-24n/aexe bb0f26097d4b901320fd0862ff2c240728f0d3bd3fa70f9a6d6f59ccf6124790n/a Formbook
2018-11-23n/aexe de27ea151d66241f2a2fc0b61369bf281a6c2ff5cd8dfab902096a3798cb07aeVirustotal results 42.65% Formbook