URLhaus Database

You are currently viewing the URLhaus database entry for http://utasarmsinc.ru/live/dew002.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182
URL: http://utasarmsinc.ru/live/dew002.exe
URL Status:Offline
Host: utasarmsinc.ru
Date added:2018-03-19 13:56:23 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?):No
Tags:ee Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-04-04n/aexe cd2eb7cb3108011dae597dfa349ad1348391a14aebcba2bfc926313d2292ce13Virustotal results 72.73% Formbook
2018-03-22n/aexe cd2eb7cb3108011dae597dfa349ad1348391a14aebcba2bfc926313d2292ce13n/a Formbook
2018-03-20n/aexe f21ff6a842e8bcf303619a1fd7c4f1a14a715dd27bc83da7e7235fc7a99b269an/a 
2018-03-19n/aexe 38bb0a1d49eb96f7fae4e2e6831184522114744b354fd2b299eafc3d76bc7a62Virustotal results 32.81% Formbook