URLhaus Database

You are currently viewing the URLhaus database entry for http://nilemixitupd.biz.pl/fktnbujgmfkgtdeitobregvdgetyhskwuendkfptojHYhkfkm/Zfmffsi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:655552
URL: http://nilemixitupd.biz.pl/fktnbujgmfkgtdeitobregvdgetyhskwuendkfptojHYhkfkm/Zfmffsi.exe
URL Status:Offline
Host: nilemixitupd.biz.pl
Date added:2020-10-05 15:24:36 UTC
Last online:2020-10-07 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-10-05 15:26:07 UTC to abuse{at}mvps[dot]net)
Takedown time:1 day, 15 hours, 46 minutes Poor (down since 2020-10-07 07:12:37 UTC)
Tags:exe Loki link ModiLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-06n/aexe 6459a9e97d4b982bd7ab59434fbe96d7e289871733e46c755eaba190728818c6n/aModiLoader
2020-10-06n/aexe d2260cf4bc6a1c1c042af5caa0c0d76c4efca389588ddef8a57108ca3f1c41cbn/aLoki
2020-10-06n/aexe b35655f68c781994bf22edcaf49e039366238da22d09c14ec373e55e7b5b0d66n/aModiLoader
2020-10-05n/aexe c82dbb4415ae4343b382743d2a6c093e82f61c69e20f206b08b3f70ac2dc88e1n/aLoki
2020-10-05n/aexe 08ec57340fc3d816f9df88c2c09bb584175a597e0f59171d2efcd640a90c343cn/aModiLoader
2020-10-05n/aexe acbe4a7874dc872cdfc133453262610ca88ab23dcaf0d30906233c127336da93Virustotal results 27.14%Loki
2020-10-05n/aexe 4593b4811c2ead447a29ce85c80dc57005ca4f202cddfbd8ef1a8ad8eea0414fn/aLoki