URLhaus Database

You are currently viewing the URLhaus database entry for https://23.95.122.112/cloud2/Cloud2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2309470
URL: https://23.95.122.112/cloud2/Cloud2.exe
URL Status:Offline
Host: 23.95.122.112
Date added:2022-09-22 00:09:05 UTC
Last online:2022-11-13 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-09-22 00:10:07 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 22 days, 6 hours, 36 minutes Bad (down since 2022-11-13 06:46:29 UTC)
Tags:32 exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-14n/aexe 8356c85fce8acdbd11c01ac4fef7f86c25f262dd77c824f8310f969ec4f5d84en/aLoki
2022-10-13n/aexe 8f0885b3ea2ab91005404905a3bf062cb7eb435ee71658c28f4852e10b9db3c0n/aLoki
2022-10-12n/aexe 0ffac76af887d1aadbc9b52dab73c169caeee8ce9905289892fae5064f00099an/aLoki
2022-10-11n/aexe 3e42cf8b782abc2372d1fda2e773caeda09fa83f0d95f8363ff456c479c26272n/aLoki
2022-10-07n/aexe 7ef390fa155ff15041b68073930fb21bba68e408525ec0ed18b6cc98b4e2da73Virustotal results 22.22% Loki
2022-10-06n/aexe b55a56ac2e31e61f967d2ccc06830afc704a4a33bec718d458f07c9cb4c36934n/a Loki
2022-09-22n/aexe 73b13cea2c234ce674dae5666bc66fe01ba387283672ccf2684735a1b8c9a643Virustotal results 35.71%Loki