URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/nnannazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2614105
URL: http://208.67.105.179/nnannazx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-19 16:21:05 UTC
Last online:2023-05-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-19 16:22:05 UTC to abuse{at}serverion[dot]com)
Takedown time:27 days, 20 hours, 18 minutes Bad (down since 2023-05-17 12:40:59 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-28n/aexe 4a340ed2bb2fa46a77fa5ef392bfe250651ae9dcb7e63a47b3c4cbc901c1818cn/a Loki
2023-04-23n/aexe b175593d1ac69bbb4ccb9d1ecac2eef8414ef9dc8bf0ff6975c63537dda6ec13n/aLoki
2023-04-21n/aexe 293e22314006f926fb7d1c66c3ed6c310c6db3fbe3d543826cde4ee2e54ba735Virustotal results 27.14% Loki
2023-04-21n/aexe b49e9522a99834cbfc85a7e5869269fd738f71592919b6e56979d2e008c3028dVirustotal results 20.00% Loki
2023-04-20n/aexe 0af4bdeb4de3a9f8cac5601c872cd4d9a7e9fb06a4fc0a7ed4fb60d6cb64b957Virustotal results 25.71%Loki
2023-04-20n/aexe 51d167499771b51338ce81d945bb083dbafbacb8256a910af55575a8f506f3e3Virustotal results 40.00%Loki
2023-04-19n/aexe 0699e889c84a872eccddfa07916b7a7e379ce6335e1796d67d119b6450323790Virustotal results 34.29%Loki