URLhaus Database

You are currently viewing the URLhaus database entry for http://sroomf70nasiru.duckdns.org/nass.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:316041
URL: http://sroomf70nasiru.duckdns.org/nass.exe
URL Status:Offline
Host: sroomf70nasiru.duckdns.org
Date added:2020-02-19 09:47:14 UTC
Last online:2020-04-12 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-02-19 09:48:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 22 days, 22 hours, 28 minutes Bad (down since 2020-04-12 08:16:39 UTC)
Tags:exe GuLoader link Loki link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-01n/aexe 5fe88d0edf17e2bcbbc22d30230f698c5229e31ca58853e9dc86b8e71cc8383an/aGuLoader
2020-04-01n/aexe c6b43505d40cb5d45abb2d4f79e6b83c7c1c0cae54e2696348bcfcf3fecdcaf8Virustotal results 13.70% GuLoader
2020-03-27n/aexe 6fd4401fa024eb06ce4f6cd259843f4c51169fc4a9baffe28c79301e951541ben/a 
2020-03-12n/aexe b6872b91d06ab3daf5a75ea8f182babc3e9c5095ec22ed800182ef9135a99925Virustotal results 13.70% 
2020-03-11n/aexe 110d8d2674eac46aa37ca96c7ae2d71a72f35a8039b9189a0ba3ceee98cc7708n/a 
2020-03-11n/aexe fa4af9f9d94bd9abce8e8d6537ea286c0e58897173525b6ae0d6a396aaf67225n/a 
2020-03-10n/aexe f1ea02019a65b994c12820c91ca3398eacda77845c87233b473b97482b682453Virustotal results 17.81% 
2020-03-09n/aexe b1a97743e4473145c51fc8339145d754e823e8d02540efd5af902648271b8ef5n/a 
2020-03-09n/aexe 33bd44a9084e78460e830f6ad97ba54a2e582efa4c37c6c7dcf8efd1078626ebVirustotal results 15.49% 
2020-03-09n/aexe 6cd0b509fcce663da59b250c13a6c955d7264a0cdf5e09bc5d79e5ac5b294c01n/a Loki
2020-03-05n/aexe a5329955947c6e3fd85048652c0d3576c05e54d6be859c7b6c68901c40a41133Virustotal results 36.99% NanoCore
2020-03-05n/aexe 2817e13619695147b41f09fb828a34e45618e56f401e5e68ee21001ead9dd51eVirustotal results 32.88% Loki
2020-03-02n/aexe 7e4ec5382c32dc4e643b0195ba819e3cf2ef1e6668b99baa5f7ae9110b24328cVirustotal results 30.56% 
2020-02-26n/aexe cf5741ec2625c386eead0aa141a60585cc5e936ad07797acc2667668bc341056Virustotal results 41.10% NanoCore
2020-02-25n/aexe c602e5a18b2a26f562427a219c916637f01df0aadbbf4988349a8e58e6aa34c7Virustotal results 18.84% 
2020-02-19n/aexe 7fda5af6776e3d2b7abc83cbdc4048c226807e6befc5ea3f34b22af8c2d151e9n/a NanoCore
2020-02-19n/aexe 26253a6b43fc41698e31e1842b86b219b8cdd4f3e726045340e7b9705297d83dVirustotal results 29.17%