URLhaus Database

You are currently viewing the URLhaus database entry for http://185.252.179.254/data/loki.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2666204
URL: http://185.252.179.254/data/loki.exe
URL Status:Offline
Host: 185.252.179.254
Date added:2023-06-19 11:05:12 UTC
Last online:2023-07-16 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-19 11:06:11 UTC to abuse{at}sukhoi-su-57[dot]com)
Takedown time:27 days, 11 hours, 34 minutes Bad (down since 2023-07-16 22:40:51 UTC)
Tags:exe GuLoader link Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-28n/aexe dd98aaea7e701f3f24539f3711010afeb2a3e794931cd9f946c285d056b30158n/aLoki
2023-06-28n/aexe 8236e441d353893420c1646df09087cfe8d2ea848976ae9f4b1b51f8cb5abaf5Virustotal results 30.00%Loki
2023-06-22n/aexe b4e77135a79b0b79c838f8bedf30ce24e0600267cdb622b2c85b5e9cab5fbfdeVirustotal results 23.94%Loki
2023-06-22n/aexe 43c259140e721cbe2d4c3a2a032a2f991fcf726844d2d258fc1e91974239e350Virustotal results 27.94% Loki
2023-06-21n/aexe 08f0f291f09041033b756c002832544f4013830b8cfde96a98e34cfbe5b39ef8Virustotal results 24.64%GuLoader
2023-06-20n/aexe e5a42d7d2e108da62811393c62da4b8c1856a1ff76631942bcda4a179d866894Virustotal results 8.45%Loki
2023-06-19n/aexe 6fac7a1f4443bf70639465110324881bdf63d2bb86e1a4397dd72a25fa1364a8Virustotal results 18.57%Loki