URLhaus Database

You are currently viewing the URLhaus database entry for http://stdyrusschine2ganmax.dns.army/documernt/regasm.exe?platform=hootsuite which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1045809
URL: http://stdyrusschine2ganmax.dns.army/documernt/regasm.exe?platform=hootsuite
URL Status:Offline
Host: stdyrusschine2ganmax.dns.army
Date added:2021-03-04 04:36:05 UTC
Last online:2021-03-06 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: gorimpthon
Abuse complaint sent (?): Yes (2021-03-04 04:38:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 4 hours, 4 minutes Poor (down since 2021-03-06 08:42:25 UTC)
Tags:exe Loki link lokibot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-05n/aexe 9b8e02c9169932cb809300c4dff5afc240aba4d5a87264f0f7123314345c6248Virustotal results 15.71%Loki
2021-03-04n/aexe a155e4a091ce6d5b565f18306521f9b383c86afa18f70272500804aba289f35eVirustotal results 30.77%Loki
2021-03-04n/aexe f3e69843ea6825d370efe74d223766268c49aac457b52ca05123fbc06d31f964Virustotal results 38.57%Loki