URLhaus Database

You are currently viewing the URLhaus database entry for http://modcloudserver.eu/billiz/billiz.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:348183
URL: http://modcloudserver.eu/billiz/billiz.exe
URL Status:Offline
Host: modcloudserver.eu
Date added:2020-04-22 14:26:25 UTC
Last online:2020-05-08 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-04-22 14:28:02 UTC to noc{at}dedfiber[dot]com)
Takedown time:15 days, 14 hours, 31 minutes Bad (down since 2020-05-08 04:59:30 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-30n/aexe 48b595428b2e25e856d4fdd098da82bc1f00f6590318bd68120a61bf67f13cb1Virustotal results 41.67%Loki
2020-04-23n/aexe 5397b13547490ea8775d45eb1b3a2c1400b72674e5d41bcc178ffdc7880f9363n/a Loki
2020-04-23n/aexe ec58f409c210611640697ac1416f8a1e2473de5937235b7ec952e24cd5d2bc17n/a Loki
2020-04-22n/aexe 7a178eb5af773199f14ca84ceaf1d67d8b4a615c215d04ab3c763e61e2ad7456Virustotal results 54.17% Loki