URLhaus Database

You are currently viewing the URLhaus database entry for http://stdyrmtcntlenverstgv.dns.army/documenrt/winlog.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1012361
URL: http://stdyrmtcntlenverstgv.dns.army/documenrt/winlog.exe
URL Status:Offline
Host: stdyrmtcntlenverstgv.dns.army
Date added:2021-02-16 06:58:07 UTC
Last online:2021-02-18 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-16 13:38:14 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:1 day, 23 hours, 47 minutes Poor (down since 2021-02-18 13:26:11 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-18n/aexe 8241caa4d6c5a09290864492d19dee143f0f80074d370135c0f91bad01c16ee3n/aAdware.Generic
2021-02-18n/aexe 9ab3bb93a6d39ab709c9b2369cde749ccbe7f3796c7c3e2fc39aa4715c3bb0fdn/aFormbook
2021-02-17n/aexe 5ec36ac5ba843f29bb0dc75d7d527ab9cee34a681bad704a89fd5ed12cdea337n/aAdware.Generic
2021-02-17n/aexe 1b349bf40b363ba0fbe4e194249ad989692b114e9004b838176b63119a259d7bn/aAdware.Generic
2021-02-17n/aexe 149bc7bb666f2eabcf946822bd316709ddeeef787f059687415f98c71ad47783n/aAdware.Generic
2021-02-17n/aexe a4ed754c1a38fd8fc24bb4ec7f5da899c254df070bcc8cfd7b16778701c4b72dn/aFormbook
2021-02-16n/aexe 6a37a2a65393b805bbe4e7e4e42b642da433e9caa7436aaeb9df8ab0fc6679b9Virustotal results 38.81%Adware.Generic
2021-02-16n/aexe 9681746b0d72e882c0949fcbdd3005b15720d66b4a8795b9d7c8c98a59048582n/aFormbook