URLhaus Database

You are currently viewing the URLhaus database entry for http://imgs.googlwaa.com/lqosko/p18j/cust9.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1685648
URL: http://imgs.googlwaa.com/lqosko/p18j/cust9.exe
URL Status:Offline
Host: imgs.googlwaa.com
Date added:2021-10-16 18:02:06 UTC
Last online:2021-10-16 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-16 22:00:03 UTC to abuse{at}scalabledns[dot]com)
Takedown time:28 days, 0 hours, 43 minutes Bad (down since 2021-11-13 18:46:48 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-13n/aexe 88554be898d01c32b08f330edfdd0c0c41e6caef8d8a6c6a78673c4639946e60n/a
2021-10-21n/aexe 97c0c04ae83b9599b78f61d809cfb2428984b25a79d2d986dfdbad6858101af9n/a 
2021-10-16n/aexe fd4d1fc83330c5cf818e557ef882ca147ba98fee4128fe00bda07c6c2f79050aVirustotal results 46.27%Downloader.Upatre