URLhaus Database

You are currently viewing the URLhaus database entry for https://xpackmx.com/SddffvVGbnmkolkjjutgvfSFRSGrgg/XZYjfbnrtjtnxsrg4008u.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:952654
URL: https://xpackmx.com/SddffvVGbnmkolkjjutgvfSFRSGrgg/XZYjfbnrtjtnxsrg4008u.exe
URL Status:Offline
Host: xpackmx.com
Date added:2021-01-11 11:31:07 UTC
Last online:2021-01-12 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: ffforward
Abuse complaint sent (?): Yes (2021-01-11 11:32:02 UTC to abusenoc{at}layerhost[dot]com)
Takedown time:20 hours, 56 minutes Good (down since 2021-01-12 08:28:38 UTC)
Tags:exe Loki link lokibot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-12n/aexe bc4bab61ab8b90451441bacba2edad8c1acd2a93c0318f4f4aa303627c4e7e3an/aLoki
2021-01-11n/aexe e01d70a2ddf0c706a1f5e4847f8c099ffdc821b188f98dc15f528c8bf34a6630n/aLoki
2021-01-11n/aexe 02944dc72a15e92ec94c453c74c9564cb59ac7717dffcb25fa854a2e587fb737Virustotal results 21.13%Loki