URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.251.29/zz/loader4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2068273
URL: http://198.23.251.29/zz/loader4.exe
URL Status:Offline
Host: 198.23.251.29
Date added:2022-03-01 08:38:05 UTC
Last online:2022-03-28 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-01 08:39:09 UTC to abuse{at}colocrossing[dot]com)
Takedown time:26 days, 20 hours, 33 minutes Bad (down since 2022-03-28 05:12:29 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-28n/aexe 951f607e9f0a0f368a363006e1c5236eadb847a91d720c803f640139f486b1a4n/aLoki
2022-03-25n/aexe 5cb102b621e23d84856b9b0f62876d6a465cda9e3147e662d635d5619bdfa3dan/aFormbook
2022-03-24n/aexe 044fad47d8e923dbb4aaa2fbc435f15990f167817d478c9b3512f3cac224b831n/a Loki
2022-03-22n/aexe 4ff5a3e73201b68518e51ffd17b1cdab8f7a45b020756d4af4a9f8bb273a686an/a 
2022-03-10n/aexe f470736f5fe9bde256388a89e8b441f37eb8b48cf82b05a729f0bab1b3bdffe6n/a Loki
2022-03-08n/aexe eb5ea817fafaf78fb281514d7cf459f4d0a51ecc7f5d75904c3fbd421a655fe0n/a Loki
2022-03-03n/aexe 4afd92f01081ab0cc7b11a50b9a5bf980f3a7aec5d3daba1952e2887b676ceben/aLoki
2022-03-01n/aexe d070985741f4469026b12984e4c55820a60dfb381da63eb86b42c8f6bb49fe23Virustotal results 38.57%Loki