URLhaus Database

You are currently viewing the URLhaus database entry for http://217.196.96.217/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2716378
URL: http://217.196.96.217/svchost.exe
URL Status:Offline
Host: 217.196.96.217
Date added:2023-10-04 14:10:23 UTC
Last online:2023-11-28 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-10-04 14:11:07 UTC to awore[dot]ru{at}gmail[dot]com)
Takedown time:1 month, 24 days, 10 hours, 34 minutes Bad (down since 2023-11-28 00:46:03 UTC)
Tags:32 ClearFake exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-07n/aexe eb755acbee492a81ad78a3e1e71e66468a7cf9a54358758e1deefcd303c9c52bn/a 
2023-10-18n/aexe 9671cf1fbaab6572611f00fbed511880a3b2a5a8ea02d0140802fa786f1ef0cbn/a 
2023-10-15n/aexe 0877c9621b5a1af2c0a872b0094d8a511fad4307154c686849230df0849dc19fVirustotal results 8.45% 
2023-10-15n/aexe f625430501e4eadbbf427911d4e29fee5e42a285a15b498fceb57fd30fb7939bn/a
2023-10-04n/aexe 65f68c86b215ee6c93a9c4f56eda6748e4af7d49589c69a3a5f96f5734468c25Virustotal results 50.00%