URLhaus Database

You are currently viewing the URLhaus database entry for http://103.133.108.17/data/loki.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2628207
URL: http://103.133.108.17/data/loki.exe
URL Status:Offline
Host: 103.133.108.17
Date added:2023-05-10 07:56:38 UTC
Last online:2023-06-06 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-10 20:42:06 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:26 days, 16 hours, 22 minutes Bad (down since 2023-06-06 13:04:24 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-03n/aexe 810da13ba4f7421fe17cb4f13922fba87106cf160da6d7b2e1201131df7dc8e1Virustotal results 59.15% Loki
2023-05-23n/aexe b31c69f348ee01781d2dac51c0380c079ae70f6bd7478971505df0400db13ad6Virustotal results 22.22%Loki
2023-05-23n/aexe fcc13ab4df58df50ab0966b6fa5434fe1a427b942a0c8c2d582fee96b8680137Virustotal results 30.99%Loki
2023-05-22n/aexe e8f32c1a6c7b43a7b6c31fb0b6e231ef359db83c384bf68105ab0af64568946fVirustotal results 23.94%Loki
2023-05-18n/aexe dfe36f30c90f653b7f3725fc4cd6efa473ce8c0a2790ca9e1c4f0c4b1e2dfa5fVirustotal results 32.35%Loki
2023-05-17n/aexe 809b7b1088f505116f19a1b08924ce48c8d8dac9856ec2f5958fef8cf81125efVirustotal results 25.35%Loki
2023-05-12n/aexe 19d6c86ef7a1f836a836dfe615377d427d6b32ff4898f417b6c728ec9f7b929cVirustotal results 60.00%Loki
2023-05-10n/aexe dbfb7fe4882a662e88d24b69b6e2fe33bafc95124d20b1db754ce05698527effVirustotal results 56.36%Loki