URLhaus Database

You are currently viewing the URLhaus database entry for http://202.55.134.71/sett/kung.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2718293
URL: http://202.55.134.71/sett/kung.exe
URL Status:Offline
Host: 202.55.134.71
Date added:2023-10-09 06:30:16 UTC
Last online:2023-10-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-09 06:31:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:22 days, 5 hours, 23 minutes Bad (down since 2023-10-31 11:54:48 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-13n/aexe 25f9c6802d033da45292618209f2ff7ca03c3207f1705e102e69f698584906b4n/a Loki
2023-10-12n/aexe a5333dbe2b5b9aad1ef0802c6ed51e62baf86e7887c6253afea8831af52c5c72Virustotal results 38.89% Loki
2023-10-11n/aexe b3b2665341f40d711d7f22a2260bee10e1c8db95b1c105bb1a5977a68c2ff933Virustotal results 37.50%Loki
2023-10-10n/aexe a72c0d696fba8a092fe459d85ab642b49529b1b156e597da55dceb8cdf579cdan/aLoki
2023-10-09n/aexe c49b74e2032051fc292bc1b3dfacc70c2b7051074c59de6f0d17929df10211ccVirustotal results 26.76%Loki