URLhaus Database

You are currently viewing the URLhaus database entry for http://ge-ck365.com/15/data64_5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2286361
URL: http://ge-ck365.com/15/data64_5.exe
URL Status:Offline
Host: ge-ck365.com
Date added:2022-08-31 07:58:05 UTC
Last online:2022-09-27 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-31 07:59:06 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:27 days, 7 hours, 52 minutes Bad (down since 2022-09-27 15:51:52 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-05n/aexe 576b1d2fbba62763b98edbe8bf8b64366b2bc7445e907dee0e55bf6999c07cf4n/a
2022-09-05n/aexe f98f9e49f55a563e7fe806c0c95c338323b67c060fa8b306cbf6404387e963edn/a 
2022-09-05n/aexe 61f15e2415bf1b2a629504593ccd25b598abb5edfcf0eeeb4b1ce28f9324cb10Virustotal results 42.86% 
2022-09-03n/aexe 1df1716541a5e718c74faff2fbcc517e3ec0b6a9ed47958bca77c59a5b1c899cn/a 
2022-09-02n/aexe d664762bc07e033a42f11964f7a086389bd6a8460a6a88f1dc30745b195d2799Virustotal results 43.66% 
2022-08-31n/aexe e295a53ac9c9ad5bc5d4c5f9487700c22a0a4d7a26e69d693f70f69e8c6e15aeVirustotal results 27.54%