URLhaus Database

You are currently viewing the URLhaus database entry for http://sroomf70nasiru.duckdns.org/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:316039
URL: http://sroomf70nasiru.duckdns.org/file.exe
URL Status:Offline
Host: sroomf70nasiru.duckdns.org
Date added:2020-02-19 09:47:07 UTC
Last online:2020-03-27 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-02-19 13:32:07 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 7 days, 2 hours, 41 minutes Bad (down since 2020-03-27 16:13:30 UTC)
Tags:exe Formbook link Loki link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-27n/aexe 6fd4401fa024eb06ce4f6cd259843f4c51169fc4a9baffe28c79301e951541ben/a 
2020-03-12n/aexe 64551b04da5c87e5ecaa8e315cdd186fac570fbf47ad3cf5eb3daf4b1138859dn/a 
2020-03-09n/aexe b1a97743e4473145c51fc8339145d754e823e8d02540efd5af902648271b8ef5n/a 
2020-03-05n/aexe a5329955947c6e3fd85048652c0d3576c05e54d6be859c7b6c68901c40a41133Virustotal results 36.99% NanoCore
2020-02-26n/aexe 2e85cf584ba9d27a085f460012d6cba62d92dcb7180c09bd79a677ee5cdf1c7an/a 
2020-02-26n/aexe 7eaa4fc5951dea20fed6d5c306f2d2462b5add60155ac2d95b94b8678e886328Virustotal results 39.73% 
2020-02-26n/aexe cf5741ec2625c386eead0aa141a60585cc5e936ad07797acc2667668bc341056Virustotal results 41.10% NanoCore
2020-02-20n/aexe 707f3965a58b4847fc16c9f911a2d80ee6370b6a293b8d109623ab73e62774f7n/a FormBook
2020-02-19n/aexe 7fda5af6776e3d2b7abc83cbdc4048c226807e6befc5ea3f34b22af8c2d151e9Virustotal results 31.43% NanoCore
2020-02-19n/aexe a88a64c5ad0856866982177747dd6b6c373378be0d237543f2471a6d4c3f92a6Virustotal results 30.43% Loki