🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://eiffelmx.com/pfgGgGGhHhBgghFufUTFDtdtDUDudrSiHIKfgf/Rzxfenjk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:973994
URL: https://eiffelmx.com/pfgGgGGhHhBgghFufUTFDtdtDUDudrSiHIKfgf/Rzxfenjk.exe
URL Status:Offline
Host: eiffelmx.com
Date added:2021-01-22 11:08:06 UTC
Last online:2021-01-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: ffforward
Abuse complaint sent (?): Yes (2021-01-22 11:10:04 UTC to abuse{at}combahton[dot]net)
Takedown time:2 hours, 40 minutes Good (down since 2021-01-22 13:50:58 UTC)
Tags:exe Loki link lokibot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22n/aexe 5e1309fe7bae5ab648156bcfe96af0a94e7452035decfbd9657c28b5fff76316n/a Loki
2021-01-22n/aexe f4f4a5953d0c87db611fa05bb51672591295049978a0e9e14eca8224254ecd7an/a
2021-01-22n/aexe 73dbbac84a2c0d3d7aa70a1daa42e6041ca3d7475ca42fe3314f3fb7c8ac9343n/a Loki
2021-01-22n/aexe 73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28Virustotal results 12.86%Loki