URLhaus Database

You are currently viewing the URLhaus database entry for https://nilemixitupd.biz.pl/zero/Qyuvbsk_Signed_.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432118
URL: https://nilemixitupd.biz.pl/zero/Qyuvbsk_Signed_.exe
URL Status:Offline
Host: nilemixitupd.biz.pl
Date added:2020-08-13 16:37:05 UTC
Last online:2020-08-14 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-08-13 16:38:03 UTC to abuse{at}mvps[dot]net)
Takedown time:16 hours, 59 minutes Good (down since 2020-08-14 09:37:08 UTC)
Tags:exe Loki link ModiLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14n/aexe 44627a0529d595d761860fa3bf49f99117335bbe8506e5e59985186f608779cdVirustotal results 13.85% ModiLoader
2020-08-14n/aexe 038233b758e4b8a9c51477272983cb36827d4ba039924cb91334162de9883d52n/a Zegost
2020-08-14n/aexe 5df73d3ff9c78a5a3b0248685c182af848603684392a906f38e95d720a8b42a9n/a ModiLoader
2020-08-14n/aexe 7f40ddf0b224f112360879ab095efadb5898a97285d2711c329aff8cc17d5101n/a ModiLoader
2020-08-13n/aexe 34105f6e5f210b18b2b65fb63f79a77314aeac4d94cba6b8d7782c252e653fden/a ModiLoader
2020-08-13n/aexe a95c6a61523704d369aa61231c2c1ae80c1ce87911f519b4108a40306b2152acn/aModiLoader