URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.73.137/dd/loader4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2188338
URL: http://107.172.73.137/dd/loader4.exe
URL Status:Offline
Host: 107.172.73.137
Date added:2022-05-10 11:21:07 UTC
Last online:2022-06-22 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-05-10 11:22:14 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 13 days, 3 hours, 32 minutes Bad (down since 2022-06-22 14:54:34 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-20n/aexe 58bcc4edf2e14afd8bf7040cd8e184806e9a930cc44f56dec6573dbfdcc578cfn/aLoki
2022-06-15n/aexe c5b5d33eac9d4387ece662c100b3bcc2fac47d060a66b5c7a080ba8ca345258cVirustotal results 30.88% Loki
2022-06-10n/aexe 87af7d77c45b0b9b8ee786a45f4f82ef2bd45e6a14935dc863c8955b9dd71417Virustotal results 43.75% Loki
2022-06-08n/aexe 604de352cfc00690d2b3f3ca1dc90665f87f7f8274e30fdc2fb82532a578e84an/aLoki
2022-05-18n/aexe f81ca03de23dffa40657f1f033f5d70117462cb232d853e9e2c326061ca32f23n/a Loki
2022-05-16n/aexe d01d91c8a0032b9f4bd1d35c94d5d67f396acd6f54cad98655a64ca80ce967cbn/aLoki
2022-05-10n/aexe 5a8972d75037e916016c48dc1ec724bffcecf961ddd320583658b066c9c5c736Virustotal results 46.27%Loki