URLhaus Database

You are currently viewing the URLhaus database entry for http://wsdysuresbonescagehp.dns.army/documenpt/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1225010
URL: http://wsdysuresbonescagehp.dns.army/documenpt/svchost.exe
URL Status:Offline
Host: wsdysuresbonescagehp.dns.army
Date added:2021-05-12 11:27:06 UTC
Last online:2021-05-15 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-05-12 11:28:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 18 hours, 11 minutes Poor (down since 2021-05-15 05:39:55 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-14n/aexe 7eb80383521475bdd6d1799392941fbaa6f1a278d59695fd056e0a8a5f6f99c0n/aAgentTesla
2021-05-14n/aexe 6d7571b2d3d4799ba199d0c56ae231b3b1078387ae1ecea2218171ae36fd4881n/aAgentTesla
2021-05-13n/aexe 52c0ec1e8a7df5f0f798b44658d94ee2c854a0c2b4a378244c60ca9c51e6b9ebn/aAgentTesla
2021-05-12n/aexe 1b80ed1165b46b410fbc236e2e19baa9e0d71b6992a41e5d30b7d70670bb2c08n/aAgentTesla
2021-05-12n/aexe 778487cdb0077cbe811443b5247a8121c5fc7c7e23472c068eee1e41a1476745Virustotal results 31.88%AgentTesla