URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ukndesw19x.com/lqosko/p18j/customer3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:942368
URL: http://www.ukndesw19x.com/lqosko/p18j/customer3.exe
URL Status:Offline
Host: www.ukndesw19x.com
Date added:2020-12-26 07:49:13 UTC
Last online:2021-01-06 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-26 07:50:03 UTC to abuse{at}choopa[dot]com)
Takedown time:11 days, 0 hours, 18 minutes Bad (down since 2021-01-06 08:08:34 UTC)
Tags:exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31n/aexe 800d090db8e4ecc0bc4afe5b9f360cb554cc29981519f654941d1d0783f6326en/a 
2020-12-31n/aexe cd029ee7b2af7abf98bc7ddbf52648b65b60e100a2ce34b781af06f4837d0be7n/a 
2020-12-27n/aexe be72e95f270735bb4f1a6fae8a9d1961c1109eb8b2bd966078fec63601eba8caVirustotal results 28.99% 
2020-12-26n/aexe a408e65fa77a4eded318a05af68fe27f522ec61b0c3e30aa34a5703b06fe2cf8n/a