URLhaus Database

You are currently viewing the URLhaus database entry for http://workfinestdyrainbyar.dns.army/findoc/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1068332
URL: http://workfinestdyrainbyar.dns.army/findoc/svchost.exe
URL Status:Offline
Host: workfinestdyrainbyar.dns.army
Date added:2021-03-15 09:24:06 UTC
Last online:2021-03-17 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-15 09:25:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 2 hours, 36 minutes Poor (down since 2021-03-17 12:01:20 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-16n/aexe 0cfcc28cdab9675c1a09f88af826490e0e35e4292d7eedf174f9dac055d8085dn/aFormbook
2021-03-16n/aexe 1b46fa95d686b11522fb3e6cc14e75eace625fd54416aa41be9dc4be51e90568n/aFormbook
2021-03-16n/aexe 850ba9cb8e16d04b40e1499ea65f614d760af29ed7f0892f99e10c88e1f80c68n/aFormbook
2021-03-15n/aexe 3ed517e03182938065c9a5d0c3e97bfc763d36e6b34b9d41472e08549a9a3108n/aFormbook
2021-03-15n/aexe d1af6aec6a4b06500ebe4f8c30b0d8870212190142a1ced3ca474c3677782a49n/a Formbook