URLhaus Database

You are currently viewing the URLhaus database entry for http://103.167.92.45/kung/GG18.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2563447
URL: http://103.167.92.45/kung/GG18.exe
URL Status:Offline
Host: 103.167.92.45
Date added:2023-03-08 21:08:13 UTC
Last online:2023-04-05 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-08 21:09:06 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:27 days, 6 hours, 12 minutes Bad (down since 2023-04-05 03:21:54 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-23n/aexe 8dbcffd97d94be3165aec10026ea0019f4dc271f39791cec1044a4851a7c5db4n/aLoki
2023-03-23n/aexe f4784f17ad8656d1ac9b926def0a4572415f35d83f979f808ea4d4c8024e25ccn/aLoki
2023-03-22n/aexe 9b121e2b55d7bd57ebcde6a362a90d941e4d7108be4438f82c1b89aa62f45ef3n/aLoki
2023-03-22n/aexe 6c04e613bc5ff2068bfcdab2681bb318fb58bc6d4b0eb3d8263d9465ae46b298n/aLoki
2023-03-21n/aexe 9da6da6d54ad5c972dd827ea8a62d7fd76dae32c2c03ef2b0b5d9fd902c7ee34Virustotal results 31.88%Loki
2023-03-21n/aexe 8dd83883d8daee30f21adb85cff72ca768a80559820dd1770399c3f5c86f52efVirustotal results 28.99%Loki
2023-03-13n/aexe 609be0559c98f1b0cfa4df0dadad1357092385ed03a501e46512b0b583869265n/a Loki
2023-03-13n/aexe b6a3b46a766ba9f0d887a9a0cb0ee17a0219598e31bd71abfa516a407d0b812fVirustotal results 21.74%Loki
2023-03-08n/aexe 6bdb4084f28f803a608a4c7297cbf2ffc188744c16dfe0c6ffc718f00eb497ban/aLoki