URLhaus Database

You are currently viewing the URLhaus database entry for http://20chnesgreatworldsportsmanofalltimeisme.duckdns.org/secure/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:367727
URL: http://20chnesgreatworldsportsmanofalltimeisme.duckdns.org/secure/svchost.exe
URL Status:Offline
Host: 20chnesgreatworldsportsmanofalltimeisme.duckdns.org
Date added:2020-05-25 05:48:46 UTC
Last online:2020-05-27 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: gorimpthon
Abuse complaint sent (?): Yes (2020-05-25 05:50:08 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 9 hours, 4 minutes Poor (down since 2020-05-27 14:54:38 UTC)
Tags:Adware.Generic AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-26n/aexe d8f59dec60ce66cced2a9237ad6e49b8a567698d67c6adee1501189713a16696n/a 
2020-05-25n/aexe 5ff8d4f4e7a47982ad40dd0338524c881824e309c548b211b68a161da5f14a78n/aLoki
2020-05-25n/aexe 2bf8f47c7374ce0eb5996652f344047fd506dd733e8371df804c514052eafe36n/a Adware.Generic
2020-05-25n/aexe f1373134d3a3c9918b566505d659c38892ec4f9af8582d010bb2ceaca4c79231Virustotal results 21.92%AgentTesla