URLhaus Database

You are currently viewing the URLhaus database entry for http://3.121.109.207/lol/dira2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:971752
URL: http://3.121.109.207/lol/dira2.exe
URL Status:Offline
Host: 3.121.109.207
Date added:2021-01-19 16:44:04 UTC
Last online:2021-01-21 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-19 16:46:05 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 day, 14 hours, 23 minutes Poor (down since 2021-01-21 07:09:46 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-21n/aexe b073ef66058998fc6ee7c61fb6eeaffe28a816f36dda995edcd1a6e893deedd3n/aFormbook
2021-01-20n/aexe 1e0ffffac4a1077450af5cd08414d45c275605cdedd7a3138a863b96ea3624abn/aFormbook
2021-01-20n/aexe 27196c6c79c8cdb02b4ee6b1028ec11aa38bbeea6d94d956a22ab1228c65b733n/aFormbook
2021-01-19n/aexe 2ad7e15e59c05d71f2682a81f2bf2872eb4421b343a4c4b96748a31064445494Virustotal results 28.57%Formbook