URLhaus Database

You are currently viewing the URLhaus database entry for https://grupodicsa.com/svcrun.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2425987
URL: https://grupodicsa.com/svcrun.exe
URL Status:Offline
Host: grupodicsa.com
Date added:2022-11-18 23:16:33 UTC
Last online:2022-11-20 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-11-18 23:17:10 UTC to abuse{at}neubox[dot]net)
Takedown time:1 day, 17 hours, 50 minutes Poor (down since 2022-11-20 17:07:18 UTC)
Tags:CoinMiner dropby PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-19n/aexe a746f67c64b7c413613db6978d8183b22048fda11abfc23967576645ef724670Virustotal results 18.31%CoinMiner
2022-11-19n/aexe 54ee0263fb993c3756f582b10dba9cff0025f48ffa8400c22f5c97461a929f41n/a CoinMiner
2022-11-19n/aexe 7e9cb3b696913bfdef0f58ca98b7d74f03d6aa836f871d5df788f4f56ad13496Virustotal results 18.06%CoinMiner
2022-11-19n/aexe ae4dd9c020bb56ecae829fc23efabb471cf823ae2227d31397c58a5ffc149244n/a CoinMiner
2022-11-19n/aexe 8f0496ad782c0321ddbf5666689a6504a0b2b24bed97e0f7c47b86ac8dbdc67dVirustotal results 18.06%CoinMiner
2022-11-19n/aexe 1fe79136a42bac10cfefc51ecf9514f6d6a83fbd5cce335967ed1599bf9072ben/aCoinMiner
2022-11-19n/aexe f969b1aabff1c1f24279895b95660fc45a241e7bb1158bf3675c87a213f325aan/aCoinMiner
2022-11-19n/aexe e871eaface7a5ec475a1fc46de2db3e184459b5b5c5c6229741999a8bf62528bVirustotal results 26.39%CoinMiner
2022-11-18n/aexe 981da982454ba43815afd77b266368652d619f0d6b11c719006de556a068e3a8n/aCoinMiner