URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ukndesw19x.com/lqosko/p19j/customer5.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:942376
URL: http://www.ukndesw19x.com/lqosko/p19j/customer5.exe
URL Status:Offline
Host: www.ukndesw19x.com
Date added:2020-12-26 07:49:32 UTC
Last online:2021-03-01 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-26 07:50:03 UTC to abuse{at}choopa[dot]com)
Takedown time:2 months, 5 days, 12 hours, 5 minutes Bad (down since 2021-03-01 19:55:07 UTC)
Tags:exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-27n/aexe 32b564b4c1eb5ee71ae45823aaa568fdd0adc22b8545424272d203ff176fd9c9n/a 
2021-01-26n/aexe bf6155050aee616b3dde64bbc42a3a0422be94e035945799ae20b0c0e35f963en/a 
2021-01-18n/aexe 105b58b45ae6ccceb8b0a057d13c0833e5b0d70c3f31b6c49f130f5bf8c48fc4n/a 
2021-01-15n/aexe fcaf8acb3ed56f5c4c0ebab81e4708faaee56c4ba65006fada3fbee5a54e19b7Virustotal results 45.71% 
2020-12-31n/aexe 21bd75d68e6f77cca60fa4c933466dfd251708a4187ede2829d64b9f5c6ae28eVirustotal results 37.14% 
2020-12-26n/aexe 85f68c16519e6f833c593ed0e6b735366c061bb808c6228d730b48e3f025a9a5n/a