URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/davincizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2656988
URL: http://194.180.48.59/davincizx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-06-10 10:21:34 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-10 11:03:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:13 days, 23 hours, 13 minutes Bad (down since 2023-06-24 10:16:21 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-21n/aexe 19c3c17fa740022b31e4737cd0a03f38f5dc0f52ed70f6a2272bdb59b74cb209Virustotal results 38.24%Loki
2023-06-20n/aexe 3342faecba3c55165e62240c1f66b76f96364883ec078643b6a17d0700b9ef61Virustotal results 25.35%Loki
2023-06-18n/aexe f71c90e78037d7c76457c4fa4816cc1544f2b93bca4a9222a9da582f7172c300Virustotal results 25.71% Loki
2023-06-16n/aexe 4c7b710cdbf291ddf58269b2157572210b80d344ef58f9d250c8dfc18e03deb8Virustotal results 22.86%Loki
2023-06-14n/aexe 2a2dffa21a0803c3d837ab4df1844a649b97c09602879b1356569b61e1cd941cn/aLoki
2023-06-13n/aexe 58036d338d5e813b0143524d21a140f38d8b58f1a531b72f7ce4a82091380185n/aLoki
2023-06-13n/aexe a5748dcf451f0661bdb05c9075327bd7ea6cb654b05140f4f2dd0b169ac26bc8n/aLoki
2023-06-12n/aexe 5c01a6552e36179e065fcc044162f061bc780efdaaac71e7b0fe94efce6b449fn/aLoki
2023-06-10n/aexe b49f61234795f9d0c4fb2800a4c45346dadec2854f96c884d2432f91c3fa13a6Virustotal results 47.14%Loki