URLhaus Database

You are currently viewing the URLhaus database entry for http://3.34.179.142/deskopc/hkcmd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:986080
URL: http://3.34.179.142/deskopc/hkcmd.exe
URL Status:Offline
Host: 3.34.179.142
Date added:2021-02-01 07:56:13 UTC
Last online:2021-02-03 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-01 07:58:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 2 hours, 42 minutes Poor (down since 2021-02-03 10:40:24 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-02n/aexe 8a432739f45c70d580007c9e4586d826507821bd978c192a5f99c51e85444e6cn/aFormbook
2021-02-01n/aexe 9c239726bedd24f4d5f3a69f59bfd2bd4e129f3edaf679549e5bf884cb141115Virustotal results 78.87% Formbook
2021-02-01n/aexe 958cedb2b814c4f1e6c4cb514d5b3eff4a816777baa9533f67f3106b4e18920an/aFormbook
2021-02-01n/aexe 0a818e0d6e682be8b8b7a4ec2becdb2de6c05d5503c6f397a63d18ccf0fa9b0fVirustotal results 8.70%Formbook