URLhaus Database

You are currently viewing the URLhaus database entry for http://103.124.105.140/guJ/1337.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2767616
URL: http://103.124.105.140/guJ/1337.dat
URL Status:Offline
Host: 103.124.105.140
Date added:2024-02-22 13:24:45 UTC
Last online:2024-02-22 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2024-02-22 13:25:11 UTC to abuse{at}serverssale[dot]com)
Takedown time:4 hours, 35 minutes Good (down since 2024-02-22 18:00:16 UTC)
Tags:geofenced Pikabot ua-curl USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-22n/aexe 97f18268b17e76ed76e2c0b67b9aa1a15d4f3a7a07adf5c274fcbb8df210e456n/a Pikabot
2024-02-22n/aexe 3536f2ec65a6459dca56d3146c29359b422027bc446c3759d74c49c0e229ccc3Virustotal results 8.33% Pikabot
2024-02-22n/aexe 84aaafbeb7656207f9ff6dcb7e9804cf6a8c490dc60305759746827ff0235c8aVirustotal results 7.04% Pikabot
2024-02-22n/aexe 53ac258fddd0aa1c0b13518c4ae7eee145360c73bfbb61ed9fd71ca775d27d09Virustotal results 6.94% Pikabot
2024-02-22n/aexe 801b529ea3173ca504af6c8ee1b48f731c5d83c4771677b0752af779a0f3d0a4Virustotal results 5.00% Pikabot
2024-02-22n/aexe 4d501bb98bd6338c0c3a7986aae4dbe1e9d436b69a6a0bf4881e0f5355898795n/a Pikabot
2024-02-22n/aexe 0551101a6be6b0432f965d6a070871759ae79c1feacfc04d382a632a4566d35dVirustotal results 11.11% Pikabot
2024-02-22n/aexe 9f1babaa14639b38d21283856887f68d943ce4336f89cb6b900f948998df3e39n/a Pikabot
2024-02-22n/aexe 22bae1e1d7d3897a6ba983e0d8c55cbac7cb49ea90760ba71bc0c1470efbf1ecn/a Pikabot
2024-02-22n/aexe b025e37611168c0abcc446125a8bd7cb831625338434929febadfcc9cc4c816eVirustotal results 15.28%Pikabot