URLhaus Database

You are currently viewing the URLhaus database entry for http://rkkrstdygorgiousejtw.dns.army/receiprt/win32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1098128
URL: http://rkkrstdygorgiousejtw.dns.army/receiprt/win32.exe
URL Status:Offline
Host: rkkrstdygorgiousejtw.dns.army
Date added:2021-03-29 05:53:33 UTC
Last online:2021-04-01 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-29 06:03:03 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:3 days, 0 hours, 44 minutes Bad (down since 2021-04-01 06:47:46 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-31n/aexe a514741f5e99ded17c767b1159e98f86ae0b918fcff56f53d365e4744104f457n/aLoki
2021-03-31n/aexe bc4637b443be8c942e64fbdeb38d8b10afed00b655a631c2811cd10399b56698n/a 
2021-03-30n/aexe 501d4cf13f1e91b23dbc5b82ce88e655e14180097c685968d0de26608d973455n/aLoki
2021-03-30n/aexe 0153fdfbc02d929c7f92cd1f4826de2d6a3db1c86cf6c7b79e90169065345480n/aLoki
2021-03-29n/aexe f56732d49b44a54bd841c98e78c86dc04719eaec2fed43c2b6429abbcf7eee60n/aLoki
2021-03-29n/aexe 525a8b4b10e2eb7067eac0ff67cffa19779019dbf5ea82f55f8b589acdd3049aVirustotal results 26.87%Loki