URLhaus Database

You are currently viewing the URLhaus database entry for http://18.197.62.51/hkcmd/bin.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:918617
URL: http://18.197.62.51/hkcmd/bin.exe
URL Status:Offline
Host: 18.197.62.51
Date added:2020-12-14 19:00:05 UTC
Last online:2020-12-15 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-14 19:02:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:16 hours, 13 minutes Good (down since 2020-12-15 11:16:03 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-15n/aexe 319795a056019b583b556b445052ec4c33446a75b7310af85bf15be00b2cf94en/aFormbook
2020-12-15n/aexe 90f2c4a6ef44f74b478893cdd505c759dbe924f984daf87726ba7e64edd091c4n/aFormbook
2020-12-14n/aexe 46a62d0c493c466428aacdd8d980868e7065e12a33216983b7efea8e013fe37en/aFormbook
2020-12-14n/aexe 8daa411eb30ad00d9be98b72d66343cd681616040c1b825a4b35bfc2a27ee1deVirustotal results 19.72%Formbook