URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ukndesw19x.com/lqosko/p19j/customer2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:942370
URL: http://www.ukndesw19x.com/lqosko/p19j/customer2.exe
URL Status:Offline
Host: www.ukndesw19x.com
Date added:2020-12-26 07:49:13 UTC
Last online:2021-03-01 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-26 07:50:03 UTC to abuse{at}choopa[dot]com)
Takedown time:2 months, 5 days, 12 hours, 4 minutes Bad (down since 2021-03-01 19:54:16 UTC)
Tags:exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-27n/aexe 86aec0cc9f86808d754b3d5251d011ca08c3ea0fec3b23bac10b25700a97b6daVirustotal results 72.86% 
2021-02-18n/aexe eebfda7afd658005ad4089adcfc3434a9358dc8feef2294d9dd1f9018747a4f3n/a 
2021-01-26n/aexe 75c08fb870860af6ef039b426f028c0c3f9bf5b4f4f5d5e506143eec2c13caceVirustotal results 65.71% 
2021-01-18n/aexe f1f9b44e10d2b4d879ffde0cf925008f6198e48b9a14c90b624e97b6bbbf3fc1n/a 
2021-01-15n/aexe 48e1b3ced99ff07cbd81beb4f341408696cf41f06bf412bdbbecd110a98fd3e9Virustotal results 47.89% 
2020-12-31n/aexe 88a401f9db3859e1198c00a37d3a48778b8f6780fddb76631a3f1afd5f60b0d8Virustotal results 33.80% 
2020-12-26n/aexe 83591d8a19e792f771276deb5ed430ab1192b51f605a9ca7386161eaf520d0faVirustotal results 34.29%
2020-12-26n/aexe 738c16eec6048c5f71ed26de2393bf75293e0e10fd9a75e30c8e47e6e8e03ce4Virustotal results 33.33%