URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.251.29/zz/loader1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2068355
URL: http://198.23.251.29/zz/loader1.exe
URL Status:Offline
Host: 198.23.251.29
Date added:2022-03-01 09:08:05 UTC
Last online:2022-03-28 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-01 09:09:09 UTC to abuse{at}colocrossing[dot]com)
Takedown time:26 days, 20 hours, 2 minutes Bad (down since 2022-03-28 05:11:50 UTC)
Tags:exe Formbook link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-24n/aexe 69f9cffe5e803f964ffa8cd28190fe2f580408c13aceceeb4d6fa40a70a967a8n/a Loki
2022-03-22n/aexe fe32fd36a13e5cc83c31e29558feed1de24432c25a731c466f1fba3b854855dfn/aLoki
2022-03-15n/aexe 09f835800a6248941746215d46b09965fe23a6d30c7d4512e360c7518f30b437n/aLoki
2022-03-11n/aexe abdaf66ee5e02f9a9f181c3807b4e04c221fb82f877c2657640b78b818245e73n/aLoki
2022-03-10n/aexe 31260e81c8d8d2389cde782ebc90ddf2e6f2fd6fb2ccfab19f08c47ba5c5be40n/a Loki
2022-03-08n/aexe 95a6e7e94584bb98686d4c6d2db1a1c4c32ccd7909172422af384ac5fad7128en/a Loki
2022-03-02n/aexe b1d74737f5430e16cb2ee4707ac986ba21fc2252d50315d2b4a77e4f278b1741n/aFormbook
2022-03-01n/aexe 444196dce9e22f023f1c442ed5e12947984890331700ab2339e177796546af6aVirustotal results 29.58%Loki