URLhaus Database

You are currently viewing the URLhaus database entry for http://sylvaclouds.eu/uzmod01/uzmod01.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:329508
URL: http://sylvaclouds.eu/uzmod01/uzmod01.exe
URL Status:Offline
Host: sylvaclouds.eu
Date added:2020-03-25 06:56:11 UTC
Last online:2020-04-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-03-25 06:58:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 6 hours, 4 minutes Bad (down since 2020-04-02 13:02:59 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-31n/aexe 2c77a2abd4237170996470817018b56e4837f3a114225f9a3a785b6778d3aa16n/a 
2020-03-30n/aexe cea74027eb5411a155748a88774d572c753566b0dff00c9c423a56053002482fn/a 
2020-03-30n/aexe cea74027eb5411a155748a88774d572c753566b0dff00c9c423a56053002482fn/a 
2020-03-30n/aexe 0b444cb586f418e65a1e8422339e29dd6aac03b724c570b75da124cfbbb81ac8n/a FormBook
2020-03-26n/aexe 99393e1166875494914abf480cc23a76bb52769eea1aa15dc35c9195efc4d28bn/aFormBook
2020-03-26n/aexe 4f40e9d89e71a890c479703315aa4244afad10a18a3620c61cb9e80c6ac86bdfVirustotal results 36.99% FormBook
2020-03-25n/aexe df48398adb6578153062b77eb0ea498763f19ccccf94fc88c7aa4db98a4b1e70Virustotal results 38.36%