URLhaus Database

You are currently viewing the URLhaus database entry for http://sroomf70nasiru.duckdns.org/major.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:316040
URL: http://sroomf70nasiru.duckdns.org/major.exe
URL Status:Offline
Host: sroomf70nasiru.duckdns.org
Date added:2020-02-19 09:47:09 UTC
Last online:2020-04-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-02-19 11:20:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 22 days, 20 hours, 30 minutes Bad (down since 2020-04-12 07:50:51 UTC)
Tags:exe Formbook link GuLoader link Loki link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-01n/aexe 5fe88d0edf17e2bcbbc22d30230f698c5229e31ca58853e9dc86b8e71cc8383aVirustotal results 11.27%GuLoader
2020-04-01n/aexe c6b43505d40cb5d45abb2d4f79e6b83c7c1c0cae54e2696348bcfcf3fecdcaf8n/a GuLoader
2020-03-27n/aexe c5a0adae661a6b8c15365fcb94d46b7c3e37b46331e21716225d711d9deaca1fn/a 
2020-03-12n/aexe b6872b91d06ab3daf5a75ea8f182babc3e9c5095ec22ed800182ef9135a99925Virustotal results 13.70% 
2020-03-11n/aexe fd4d7c392a83a4f08b076632776dcd80be71a6a2f60aea6b110a0a665e33f60cn/a FormBook
2020-03-11n/aexe fa4af9f9d94bd9abce8e8d6537ea286c0e58897173525b6ae0d6a396aaf67225n/a 
2020-03-10n/aexe 39474d813ada39c7b594ab7508c7ef788dd2ef0ec929d85e50a7c8b9e11e5e06n/a 
2020-03-09n/aexe 58061bda8472614fa7660f2c6747e894810230244c223de529d4351296f27210n/a FormBook
2020-03-09n/aexe 44ed06eecb702f415c181d872562826f4f44a7b22e4f9439352fd2a675e0aa5cn/a FormBook
2020-03-02n/aexe 7e4ec5382c32dc4e643b0195ba819e3cf2ef1e6668b99baa5f7ae9110b24328cn/a 
2020-02-26n/aexe cf5741ec2625c386eead0aa141a60585cc5e936ad07797acc2667668bc341056Virustotal results 41.10% NanoCore
2020-02-25n/aexe e641f15e574633484f841d27b30d6d9a501736219b79a629be159fad3aff52aaVirustotal results 11.27% Loki
2020-02-24n/aexe 97601f2d163668b7302c60928d4e285d039637f607e470a96742ec00854cb647Virustotal results 31.51% NanoCore
2020-02-19n/aexe 7fda5af6776e3d2b7abc83cbdc4048c226807e6befc5ea3f34b22af8c2d151e9n/a NanoCore
2020-02-19n/aexe 70e2269739698e20a20e46fb7aec538c9788dd1f1bd9e586c47dc336a537682dVirustotal results 33.33% NanoCore