URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ukndesw19x.com/lqosko/p19j/customer3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:942371
URL: http://www.ukndesw19x.com/lqosko/p19j/customer3.exe
URL Status:Offline
Host: www.ukndesw19x.com
Date added:2020-12-26 07:49:13 UTC
Last online:2021-03-01 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-26 07:50:03 UTC to abuse{at}choopa[dot]com)
Takedown time:2 months, 5 days, 11 hours, 59 minutes Bad (down since 2021-03-01 19:49:15 UTC)
Tags:exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-27n/aexe 01e97016d5b84182372f1775215600b51625bdaa7ce5100a9a281260d4944894Virustotal results 67.61% 
2021-01-26n/aexe df0db0127b921044a1061db6470f444405680698781d1ad48ccae617f682605eVirustotal results 57.75% 
2021-01-18n/aexe da4ec9131c3b6452286c5277a9e8e5f874c1b1f4fac4cc07aa5be372db0c4da6n/a 
2021-01-16n/aexe b0d747c0f110f306e2c7f9e920bdaafa458560a175733ad1822a9964cbf71cd5n/a 
2021-01-15n/aexe 8d553107b870a4f4739d7467013ea82268c03d674a441b17f65aee3f4ac0db4aVirustotal results 67.19% 
2020-12-31n/aexe cd029ee7b2af7abf98bc7ddbf52648b65b60e100a2ce34b781af06f4837d0be7Virustotal results 36.62% 
2020-12-26n/aexe 9e7babad53c8a852391f9ea81a511f97a925935e537b02b45585880ef13f7aeen/a
2020-12-26n/aexe 04193de190b7ea11a42aa8e96af305d14c82d5296eca99c7379418dabddf5dcan/a