URLhaus Database

You are currently viewing the URLhaus database entry for http://sureswsdybonescagehg.dns.army/documenpt/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1148197
URL: http://sureswsdybonescagehg.dns.army/documenpt/svchost.exe
URL Status:Offline
Host: sureswsdybonescagehg.dns.army
Date added:2021-04-21 08:49:06 UTC
Last online:2021-04-24 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-21 08:50:07 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 21 hours, 46 minutes Poor (down since 2021-04-24 06:36:20 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-23n/aexe 5d37ef7ef7aa80645b2bab3596f23201678416a65fcb9a688e54d390873c68e6n/aAgentTesla
2021-04-23n/aexe 594e5e7849de748d1004f6909873e97d8cad8d439aef94a57846efb4a772e735n/a AgentTesla
2021-04-22n/aexe 8f268deb079911e8ce73341d705453e139c0169bb8d365d2ce5b77d0b6ad469an/aAgentTesla
2021-04-22n/aexe 87333ef0fa9e3210c9709eb296c413dfe6643eb8bdedf9f8ad1da0ee31da7300n/aAgentTesla
2021-04-22n/aexe 204be90329c4af31f98f140bdbd6f5a51c824cd76ff43711b498c250acfc78e4n/aAgentTesla
2021-04-22n/aexe e86e3589d2cdb4f9928d6cd64030f1d57009f241664cdde4fa88f456be92736an/aAgentTesla
2021-04-22n/aexe 3c495573fe4e2b6630e6f55de00497568ba9ad91e5aab44a3c6f59869e9c421en/aAgentTesla
2021-04-21n/aexe 65778b8834d7849f816c747ae7f3dfc5466ded7781b34959d53cb1a544aaeef5n/aAgentTesla
2021-04-21n/aexe b594f2b6d50e582013fef6de01449d3808940f119221efd40bd1775170dfcaecn/aAgentTesla
2021-04-21n/aexe 20359c84189b6e46bea8c9ae514d2d7cc315341f1ebb93d7d6a9859fc54b92een/aAgentTesla