URLhaus Database

You are currently viewing the URLhaus database entry for http://104.245.241.219/txt/sCIPrhZt5Yub9qL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3490325
URL: http://104.245.241.219/txt/sCIPrhZt5Yub9qL.exe
URL Status:Offline
Host: 104.245.241.219
Date added:2025-03-25 16:48:05 UTC
Last online:2025-03-27 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-25 16:49:06 UTC to abuse{at}virtualine[dot]org,abuse{at}vitalkey[dot]io)
Takedown time:2 days, 0 hours, 19 minutes Poor (down since 2025-03-27 17:08:43 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-27n/aexe 353f0431abc35f4de737193828be509e69003e0ba6e917e60aa5ce6c025d98a0n/a Loki
2025-03-26n/aexe 803314d516cb803d9c61b7f0df4b49cb3ed68e29ef80b2a2761f4258425a9475n/a Loki
2025-03-26n/aexe b2b9b4ee2a4edc1926c1bfdfa07061968a2e8f3685f5cae15bfbe4723f9156c9n/aLoki
2025-03-25n/aexe 1ecc198e5201c2c75116d69ff26703342f7b6c854edfbb9c0af6b3271f05a42en/a Loki