URLhaus Database

You are currently viewing the URLhaus database entry for http://202.55.135.143/user/.dllhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1566428
URL: http://202.55.135.143/user/.dllhost.exe
URL Status:Offline
Host: 202.55.135.143
Date added:2021-08-26 12:24:15 UTC
Last online:2021-08-28 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-26 12:25:44 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 18 hours, 1 minutes Poor (down since 2021-08-28 06:27:22 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-27n/aexe 295a2b49624e25f2bda364955227cdfb704462029876ac0d81e806ef22935d97n/aLoki
2021-08-27n/aexe bce59dc35407ef6fb0189206cdf64aeb937f55a4b944f6183893df5e9bd1befbn/aLoki
2021-08-27n/aexe ab163346227b7520a1f31e2e0445e25e6b77e6ba7c5e79126cb7b736a9330714Virustotal results 20.59%Loki
2021-08-26n/aexe 206ffaee571e12d28029dc615f16722fd3309c82cfc441fc304e770a6bb1d881n/aLoki
2021-08-26n/aexe 182e812e513e525d23ce63ce6f1446001b8156c9b37e97806ecbfb3c14693bc4Virustotal results 45.59%Loki