URLhaus Database

You are currently viewing the URLhaus database entry for http://89.40.14.62/servces.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1400108
URL: http://89.40.14.62/servces.exe
URL Status:Offline
Host: 89.40.14.62
Date added:2021-06-26 06:35:06 UTC
Last online:2021-06-26 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-26 06:36:04 UTC to abuse{at}iv[dot]lt)
Takedown time:12 hours, 32 minutes Good (down since 2021-06-26 19:08:10 UTC)
Tags:DarkVNC exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-26n/aexe ab09755330cc024b644d702a375c9074b6b0f25fdc0cd4b0ece7023c837fc190n/a DarkVNC
2021-06-26n/aexe aa5d834a8ded4e96b3915638955ffbf8e41a2a6276c89f1e1ff1bb172cad79c0n/a DarkVNC
2021-06-26n/aexe 9aff34a19788e17301c9961fa918554e240a183b499a3e107983d3016af4be98n/a DarkVNC
2021-06-26n/aexe fe9930ffb507511c20027f1a573e90b2c85b0befbb9167f689bcc55c3e5798a7n/a DarkVNC
2021-06-26n/aexe c26e69041f1e5635637de60643588436e059df372d4eabe94bd9620b9c9c4eb7n/a DarkVNC
2021-06-26n/aexe c3210c995f69f83e7fc8f24aa4c8510d56d6b3bb7808eaa5e78fdc383c3c24b4n/a DarkVNC
2021-06-26n/aexe ee722c86d5bded1780e620c7de6b90f694084a018cce77d4d352b3e06b97e122n/a DarkVNC
2021-06-26n/aexe 8ed4d5fead4e0eac276b6cef87d6291fcb836947c2ee9979893e3dfbc015b841n/a DarkVNC
2021-06-26n/aexe db6707dfd3c466dd3265628f922abb9908916f58ee47d9575cc45233a858e3fdn/aDarkVNC