URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.221.179/aman/krest.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2273244
URL: http://198.23.221.179/aman/krest.exe
URL Status:Offline
Host: 198.23.221.179
Date added:2022-08-16 07:12:06 UTC
Last online:2022-08-31 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-16 07:13:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:15 days, 6 hours, 3 minutes Bad (down since 2022-08-31 13:16:47 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-19n/aexe c3c88d427086092e3a59a6a1aed2d60622d6d7f3f0ddbbc0bbe4d7ad8cb8381dn/aLoki
2022-08-18n/aexe 890e54c012be66a14443f1ae6c30cbee3e7a9b7e135076913c01018bbb69f997Virustotal results 84.51%Loki
2022-08-17n/aexe 83ce4d12583639df7dcbe4d13b6e608bca3c42a58dc4fbb18c352fa93dec7800n/aLoki
2022-08-16n/aexe 1e7a3f06df19293f86631814c71e8a2ff3a9462e6576cb0b0ede5d67df5c2535n/aLoki
2022-08-16n/aexe 3453147d493dd87daa77a4c0049c6d7edfb1c80f4f3f3f10cd2e9b16ade25a12n/aLoki
2022-08-16n/aexe db68c2825bd2c49304f34315164e7be64101f04e4de1dfe2dddc14cab5610b78Virustotal results 38.03%Loki