URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.27.36/alhaji/juju.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1833640
URL: http://172.245.27.36/alhaji/juju.exe
URL Status:Offline
Host: 172.245.27.36
Date added:2021-11-29 21:03:05 UTC
Last online:2021-12-28 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-22 10:57:26 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 months, 3 days, 8 hours, 42 minutes Bad (down since 2022-02-01 05:47:06 UTC)
Tags:32 exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-25n/aexe ab4e941fa8e1a10f442c40296bbfc05e8ecd11ea248cf9a7e2fd63e4b804c35fn/a Loki
2022-01-17n/aexe ed5dd750b015972fad51710f5d8df085ad2a5ba634766f317509aebc4c941aabn/aLoki
2022-01-16n/aexe 77a366863ff591784b7bd49c858334ba697a81b71650770ef385ffd10f17d900n/aLoki
2022-01-16n/aexe 51dac63efa68f62238db30e476b708200e966e18b451cbca541f3a8ccf0e1419n/aLoki
2022-01-16n/aexe 59328c6206a431b09e8d62bcbc04b72dcb2d600218a0ad8728e5babf8c5aa191n/aLoki
2022-01-14n/aexe 87d380f12b61ff49af7680e3dd4cb7c0415be71811a565fa4736c6430e629974n/a Loki
2022-01-13n/aexe 1cdf3ccedd5b809baacb7a16b2bcdc6887fb238c4626cc8100ba4da9acff28d1n/aLoki
2022-01-11n/aexe 25d4899163cbc2e03d3aac12c292f05ac3ed86267a3d98a3cbe17d8671590879n/aLoki
2021-11-29n/aexe d999265961e40ae57957a5355fc759fb3a207650450cc0704f30ede691d96e41Virustotal results 31.34%Loki