URLhaus Database

You are currently viewing the URLhaus database entry for http://146.70.35.211/setoff/kung.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2735905
URL: http://146.70.35.211/setoff/kung.exe
URL Status:Offline
Host: 146.70.35.211
Date added:2023-11-28 07:16:10 UTC
Last online:2023-12-03 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-28 07:17:05 UTC to abuse{at}m247[dot]ro)
Takedown time:5 days, 13 hours, 29 minutes Bad (down since 2023-12-03 20:46:58 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-01n/aexe 0d8258ac56cfebd66cdab0a4a75e6938107978f6314c2e287089abf9009cad44n/a Loki
2023-12-01n/aexe e6e976b672161b8097aa6832411df6d9b1fbd9e53b8cd1f83dc0768918cdbc98n/a Loki
2023-12-01n/aexe a0d98962965a9d319aa298f072dbacfd5152f3a73d707fa51c9aa9852592607dn/a Loki
2023-11-30n/aexe f583247c60180a43d7671dfae2816bda1d33e4bf07097163cfd2b218718e980cn/a Loki
2023-11-29n/aexe 20cbc305a13eb6e310a6f2c2bddc21e5cfef33adf0f8fa31a93231c475fbc82en/a Loki
2023-11-28n/aexe bab0471833dd6077c5dbf973fec9c438f46761ccac4f613afe3302b3a7f836b2Virustotal results 52.86%Loki