URLhaus Database

You are currently viewing the URLhaus database entry for http://joejoestdyhegrenfxcj.dns.army/documenjt/regasm.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1060975
URL: http://joejoestdyhegrenfxcj.dns.army/documenjt/regasm.exe
URL Status:Offline
Host: joejoestdyhegrenfxcj.dns.army
Date added:2021-03-11 09:31:07 UTC
Last online:2021-03-13 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: gorimpthon
Abuse complaint sent (?): Yes (2021-03-11 09:32:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 13 hours, 54 minutes Poor (down since 2021-03-13 23:26:08 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-12n/aexe e9e6188efc11359d75e75bf67c28b7579ddcb507ad10afea8c721d4e8bd5e470n/aLoki
2021-03-12n/aexe 22974bdf9bc9bb3d9aa35a21377f7d8d178ba35d65fca200cf2b627b0ee0e2d9n/aLoki
2021-03-12n/aexe 319859aa3af3d46e72837db20ea4f62787520ea70941cc5a0c6fc4fe81242ad6n/a Loki
2021-03-11n/aexe b7bb35d04c43970a32711eb06080774b5b1d56260fe28b8f7c65206372943e7cn/aLoki
2021-03-11n/aexe 483d6ae983874e7a225f99747d490194256ace1b9ca6e0457dd871c70b4f83d1Virustotal results 10.61%Loki