URLhaus Database

You are currently viewing the URLhaus database entry for http://stdyrmtcntlenverpibf.dns.army/documenrt/winlog.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1068333
URL: http://stdyrmtcntlenverpibf.dns.army/documenrt/winlog.exe
URL Status:Offline
Host: stdyrmtcntlenverpibf.dns.army
Date added:2021-03-15 09:25:06 UTC
Last online:2021-03-17 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-15 09:26:02 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 1 hours, 57 minutes Poor (down since 2021-03-17 11:23:42 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-17n/aexe 1135dd1add5582b252fe397ecf075bf400d0f63c085daacaffd20f753700b00an/aAgentTesla
2021-03-17n/aexe b60294d835ab78cd6edb940a020d476704f528f65b9e03559ed53cc182c808c8n/aAgentTesla
2021-03-16n/aexe f02213dd373e6d5d9bea4f366b2cfd983e278731be7d59171de6be27a482becfVirustotal results 14.29%AgentTesla
2021-03-16n/aexe 4bc0559cbf4ec33e38c556bc91fca79005454ec4b72e1101638fc4e2bfcbbb70n/aAgentTesla
2021-03-15n/aexe 12ba7ec686abc93ded62d6cf7df6907b348988897505efde9a4447b49ee92e74n/aAgentTesla
2021-03-15n/aexe 06e0915f51d8623be912b10a59ee9f601874a0710116be2c749880339535ec56Virustotal results 31.88%AgentTesla