URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.76.132/alhaji/chief.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122752
URL: http://107.172.76.132/alhaji/chief.exe
URL Status:Offline
Host: 107.172.76.132
Date added:2022-03-30 15:40:05 UTC
Last online:2022-04-21 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-30 15:41:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:21 days, 13 hours, 36 minutes Bad (down since 2022-04-21 05:17:48 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-19n/aexe c1dab934273b95b881f27a15bb86912416d3d0dc7fb7f3942c7e441593676fa6n/a 
2022-04-15n/aexe b53d87bd0dbcedef27a6decea03580aa8e5e5ddcc71f43c6b3fa0ecc062485c4n/aLoki
2022-04-13n/aexe c7860ea8bb148187786b73f2925fd991782348282fbc71cab1cb143b2f888d56n/a 
2022-03-31n/aexe 01ef8e7e9b826da7ce9f9a6196efb6cf13e764ed594ca4224773376b3328f6b4n/a Loki
2022-03-30n/aexe 82cff514573cb3d4caf405b64b3d825bcb84256c4d42ce2db3ba6e4db37d4c87Virustotal results 38.24%Loki