URLhaus Database

You are currently viewing the URLhaus database entry for http://103.207.39.127/msoffice/csrss.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2247305
URL: http://103.207.39.127/msoffice/csrss.exe
URL Status:Offline
Host: 103.207.39.127
Date added:2022-06-22 15:24:06 UTC
Last online:2022-08-29 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-22 15:25:06 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 months, 7 days, 10 hours, 36 minutes Bad (down since 2022-08-29 02:01:47 UTC)
Tags:exe Loki link opendir Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-08n/aexe ef0c16febbe5e3351dca655081c3f6d7c6d177b2475cf3d87a307380f621a522n/a Loki
2022-08-05n/aexe 736330aaa3a4683d3cc866153510763351a60062a236d22b12f4fe0f10853582Virustotal results 2.86%Quakbot
2022-06-27n/aexe 8b9c5f48425e0dcce34f336a7c1968206ec02b73164af8a43ed120f3815e2889n/aLoki
2022-06-26n/aexe da02aad6ce84928cffd82dbe51e421a410e4415b176c3cbc11a140841e160f94n/aLoki
2022-06-25n/aexe bc7eb1d80073c55260dc05abce46ceb62c847d46f3e1c0a164cff97af8d09a1an/aLoki
2022-06-24n/aexe 0882aaf40d53091438bbf9523d43aeb448e2c01fd786f3b66a7abe19490e8c42n/aLoki
2022-06-24n/aexe 0c33915831c2f339a3185a4e3ccce8a607f9da8dc962334a5a17f0d2ef9cb09cn/aLoki
2022-06-24n/aexe 8086f063f1f9640c75170812c19f8fc1e33db3b83cb3c167150c4529dc036140n/a Loki
2022-06-23n/aexe 748eaf926943f0130b633506282d02f29da4d42d2172b3afce65246633994326n/aLoki
2022-06-23n/aexe 9896eb8d45fe829a6b491f9aabbd03b35b71aefb9645dc85578cb6365fe2ecffn/aLoki
2022-06-23n/aexe f0dfa57c34ed5491fb7d8cfa7958174454e663effd17b9d5c0e981105bbea9cbn/aLoki
2022-06-22n/aexe e9a4a25b66b32dc8de0543704765c91f942d90c3fef91c5ff16c1f2a5930aebcVirustotal results 32.84%Loki