URLhaus Database

You are currently viewing the URLhaus database entry for http://meganmall.ga/~zadmin/cwd/9ap.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:424617
URL: http://meganmall.ga/~zadmin/cwd/9ap.exe
URL Status:Offline
Host: meganmall.ga
Date added:2020-08-05 07:46:36 UTC
Last online:2020-08-19 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-08-05 07:48:03 UTC to abuse{at}selectel[dot]ru)
Takedown time:13 days, 22 hours, 58 minutes Bad (down since 2020-08-19 06:46:42 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18n/aexe 1b0f25b9bf0c76f9a52d3f5952f47b203e7112c72f8234d51155442bddddd42fVirustotal results 1.43% 
2020-08-18n/aexe a91a2fee2c92252d81b361b25f6f59206bec285b72fb16668cfb3f763fed6798n/a 
2020-08-16n/aexe 4ec8f45cc239f5a961458515e6e60bc4045a6c7d8a6d348c793e1ac3b7d00bd0n/a 
2020-08-13n/aexe 0724bc0b4abf5e1ae32a9fb01f6a9e18b6d5f086f8b19c3d41cd172fbf57e6bcn/aLoki
2020-08-13n/aexe 4da78171535f6cac47cc2036732466172fc9baa2e25bcfd3580fc28c7fdc03a9n/a Loki
2020-08-12n/aexe f0e2e080166406744cb6481cbfd1b077fcdf8feb618f23108d0f27c4e451ffcbn/a Loki
2020-08-10n/aexe 4bfa05cd7b99febfc8a1fc9384b24cd0c4a313ea79f519885db706825a04a092n/a Loki
2020-08-10n/aexe cb04e4e0e4c41fe7ab03dde2522a181761acb34360c613e5f4f85f6991c5f889n/a Loki
2020-08-09n/aexe bb85f8d47a2e364d0c20980d7bc6637b4bca353aaf083b5612cbc3ba8b1a73a9n/a 
2020-08-06n/aexe 99648118478a249b85f2c4e245ea642d0bdfaf029c013652cf0bed9c381704a2n/a Loki
2020-08-06n/aexe f24ba3f7acbd2c5dcdc1a3a4d92d36e0c882dc56ad022ad88695e432e3d75297n/aLoki
2020-08-05n/aexe 3d8cf478e496182ae32a54994a79720e6b5d79e0237e14287290fec3b22fe0bbVirustotal results 18.57%Loki