URLhaus Database

You are currently viewing the URLhaus database entry for http://wsdykungsb2talenwsjf.dns.army/kung2doc/winlog.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1104232
URL: http://wsdykungsb2talenwsjf.dns.army/kung2doc/winlog.exe
URL Status:Offline
Host: wsdykungsb2talenwsjf.dns.army
Date added:2021-04-08 06:27:05 UTC
Last online:2021-04-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-08 06:28:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:8 days, 20 hours, 51 minutes Bad (down since 2021-04-17 03:19:23 UTC)
Tags:exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-16n/aexe 16adf874a7e5757b26b6679428f4a20fc06b73f08ef776161e44bdd9e64ffb33Virustotal results 31.88%Loki
2021-04-16n/aexe 3acdd13ae0b7a4e42a3affdeb83afa699b3ebdf82c672dfbe7e41488b450f500Virustotal results 28.36%Loki
2021-04-13n/aexe 9f54ec8bc3a20410a4a0307c1e00e098e27c607963867cab80fc1766d69f97dbVirustotal results 36.23%Loki
2021-04-09n/aexe 84e98f3890f5726bce09f463487b93b93de8edff0ba96fb07e06631422ab71d0n/aLoki
2021-04-08n/aexe 4061fb72cf023e7dbc619c0d3ee7c66e1acbb3810aba3fae2592f400d4ee1006n/aLoki
2021-04-08n/aexe 90264601dc078ff9628a36dcca7a4ca0c65c7c68315601f6688f2690847fdab7Virustotal results 24.24%Loki