URLhaus Database

You are currently viewing the URLhaus database entry for http://103.145.252.216/fwkdoc/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1306418
URL: http://103.145.252.216/fwkdoc/svchost.exe
URL Status:Offline
Host: 103.145.252.216
Date added:2021-05-31 07:41:05 UTC
Last online:2021-06-18 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-05-31 07:42:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:17 days, 22 hours, 16 minutes Bad (down since 2021-06-18 05:58:49 UTC)
Tags:exe GuLoader link NanoCore link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-02n/aexe e2196feb7bc573c566561a7e80d2ae7649e93fdfb114746d190d6fa9767b13f4n/a GuLoader
2021-06-02n/aexe d6ad9479839b7c1e35a61ac244e42431e23de9be91794df9c5d027d7d1bb8c58n/aNanoCore
2021-05-31n/aexe 10b42560903d6d2fe79b9450f56dae0d2a19960cda5d53b8b70b7f7a075bb2ean/aGuLoader
2021-05-31n/aexe 7a84aa92f81ee3e9e694a8105b94a825147abf2504572a8fb3fb333d574bd33fVirustotal results 40.00%NanoCore