URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/jokerzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2648729
URL: http://194.180.48.59/jokerzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-06-01 10:07:05 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2023-06-01 10:08:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:23 days, 0 hours, 10 minutes Bad (down since 2023-06-24 10:18:57 UTC)
Tags:Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-16n/aexe 5e0a6bf1cb4d379d238d51cdab8bd64b47c10c2921f3f2cb1f6da2b33c8ac332Virustotal results 22.54%Loki
2023-06-15n/aexe 32c097d0b73a185f3cebca40dc05e17522cb1823e26aa397eb29987a58c7ef2dn/a Loki
2023-06-14n/aexe ac074ca6d2e13bcfc138958af02d7d76e20c9288360628d1a4da335fe7dd8714n/a Loki
2023-06-14n/aexe d4d5c2bde863b0196fa0892944cf52c51b1d54d018eee7b07f1f04091b4aae6cn/a Loki
2023-06-14n/aexe 82f14f2328af922009bb022e324ef028b09b2570981c3d98b2a29957829a0b0an/aLoki
2023-06-08n/aexe c912b2a9acf662b5c1ab08866b615b7d4ea24b42ccbd1078ce758ae95c4497a1n/a Loki
2023-06-05n/aexe ab8ccaa75949e4dd18a85d6b6196fb9ca71b98ed1b32d459811e530044decf04Virustotal results 15.49% Loki
2023-06-05n/aexe b0bc9570f1a138aa4d33656df1a3aa58a0a132cbc238485c839466d37c3858c0Virustotal results 30.99% Loki
2023-06-01n/aexe c7b3ec3ac46bb0ccc41cde29a371ed3c84aff73d70ddd668f2c5bcb5ba3b2819n/aLoki
2023-06-01n/aexe 62f9177d6df399011d15965044b96840df53829d8e7a391bd25395d36d39b5b1n/aLoki