URLhaus Database

You are currently viewing the URLhaus database entry for https://fvia.id.vn/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2745294
URL: https://fvia.id.vn/update.exe
URL Status:flame Online (spreading malware for 1 year, 11 month, 27 days, 14 hours, 35 minutes)
Host: fvia.id.vn
Date added:2023-12-30 10:50:08 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Xev
Abuse complaint sent (?): Yes (2025-11-05 05:15:16 UTC to abuse{at}cloudflare[dot]com)
Tags:Formbook link ModernLoader xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-10update.exeexe e205e4389101f566852855ce062cbdd7e5d475a2e81309ab89cc4ea8deba61bbn/a 
2025-09-04update.exeexe 8d1523bbaf9cccd544215c1dec33d97aa6cd4273dc4bb6469823c1385626d233Virustotal results 61.43%XWorm
2025-04-27update.exeexe 920bd5379685da509856bd7f3430beaa180cf9e684f13e922daa3f5c98e18e5dVirustotal results 77.78%
2024-01-18n/aexe d455ab58085b8733966b3f9dc23719a3f7060d466b304382e71b59ca8375cc33Virustotal results 44.29%ModernLoader
2023-12-30n/aexe 305d577ac000205cc16ac065733fdb82ae5a352ba6c3514dfb4283bef9f07a36Virustotal results 74.65%Formbook