URLhaus Database

You are currently viewing the URLhaus database entry for http://103.167.85.37/kung/GG18.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2534421
URL: http://103.167.85.37/kung/GG18.exe
URL Status:Offline
Host: 103.167.85.37
Date added:2023-02-08 19:04:11 UTC
Last online:2023-03-02 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-08 19:05:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:21 days, 7 hours, 4 minutes Bad (down since 2023-03-02 02:09:14 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-16n/aexe d01d4d39fc024afaa3f2f512b0be98db7e00079eeb40ff206ac0bc8f015a74ban/a Loki
2023-02-16n/aexe a8baf23ad89c7b3aad3df0de3d5998ffe609dbf06a9aa07fa3280717bb9cdca5n/a Loki
2023-02-15n/aexe 794bb2546616a157dfb2db80730ff92629f1f3cfc8ec99eeb9643a8c75a91ca6n/aLoki
2023-02-15n/aexe 4f019fb85247efea723c8c89294633561f3755f9a8589ecd5a38722eb75dce11n/aLoki
2023-02-15n/aexe a2f883816cebe920f0ecedef7cdfb583c6db7839c92407eae2aff6223b554f3cn/aLoki
2023-02-14n/aexe 33c537a439bc6cc87c2655b05aa895ea63a56ca0b03e0955923e92684b56e100n/aLoki
2023-02-14n/aexe dcb2d21512f81c0cc1b9eb765a3cef095c48b0d240d423b17cf4597829cbd5b1n/aLoki
2023-02-13n/aexe 4771d59089777e85be6cc8419d3f8479a0b13ffb80e11625166e9b97dfa5e826n/aLoki
2023-02-13n/aexe b025aa736501aa8e35c72ffdab8eb87129ee252e5a74ecb9a03681cede5ae077n/aLoki
2023-02-13n/aexe 27254791031b7dccc677b1234dfa8165ed0c92c2d52dbd8de521be3d91b85b5cn/aLoki
2023-02-13n/aexe 8173d1af58c6af4401204a92eba5ac55a3163a6a258eac78048db90fb1a5e72an/a
2023-02-12n/aexe 23a7f29def558c98b1d41dcf343901d5267c2d3bb3a7484598f33597c32680b7n/aLoki
2023-02-11n/aexe d14092e097c64505ef9af813bdecc55d8b2f5ab204bdc4b4e2feea2b3101a237Virustotal results 64.29%Loki
2023-02-08n/aexe 8c61d61c9162a6735ceb53e4109851feacfb05f2dee42ead799680cf874ec903n/aLoki