URLhaus Database

You are currently viewing the URLhaus database entry for http://docs.dochase.com/b.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:807970
URL: http://docs.dochase.com/b.exe
URL Status:Offline
Host: docs.dochase.com
Date added:2020-11-11 18:01:06 UTC
Last online:2020-11-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-11-11 18:02:02 UTC to abuse{at}hetzner[dot]com)
Takedown time:15 hours, 33 minutes Good (down since 2020-11-12 09:35:49 UTC)
Tags:CobaltStrike link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-12n/aexe 31ea3b1e0792ad42c5127b11d30ada34e5241bfdaf5d6b14860945d3084d4905n/aCobaltStrike
2020-11-12n/aexe 5431a9302ef3a26a356303fc023cd1407bf4d517ee4589412fef79606879cbcen/aCobaltStrike
2020-11-12n/aexe 636072602927954e7b51329968d6afe084bf7554878c158004e8b0bfd5cb1100n/aCobaltStrike
2020-11-12n/aexe 070e94ea601c76a96f0b237f76e9747852a6e555bd0c199161a62d28d69c34f7n/aCobaltStrike
2020-11-12n/aexe eb358b418965336bcfb6badb5577ce68cb69fba65f52332af34834ca2b2023d9n/aCobaltStrike
2020-11-12n/aexe 2ed6caedb9d58087892a4ff2e966f82bcd4e8e2c530aa90fc659c7d61eb327c1n/aCobaltStrike
2020-11-12n/aexe 97c5e481b724ddbc7fa39006c19f024f537a8b1e6e02d233b6588d2264dde25fn/aCobaltStrike
2020-11-12n/aexe c1c941403bca68142cc25df9f218bb8877d5a63007260e041dd1bf5db095af3fn/aCobaltStrike
2020-11-12n/aexe 0d10ff57bd06aeacd5d947019399ff2635a5b42fab0be39014c945a7588826d0n/aCobaltStrike
2020-11-12n/aexe 6515daf821f1ba10e5de6f707423f28f48cc80149a44bbfc3331fe24b9a2c3ecn/aCobaltStrike
2020-11-12n/aexe fe64ad3b5e6c425000bcab6e4c997560d4d325d2191062b26403b0a49cf53898n/aCobaltStrike
2020-11-12n/aexe 642bf0c02eef2b88a4292b09022f6068bedb4a1e3870249e7840dd3851222278n/aCobaltStrike
2020-11-12n/aexe 4aca4ba4e12e952c9eefb7d5554a806dcd5a572d1ddcf054251e4c1919e6fa74n/aCobaltStrike
2020-11-11n/aexe a50af9fb8e00f47b558e2f8e25de4aea67227f0b4120eaaacff3215af2c5258en/aCobaltStrike
2020-11-11n/aexe 27f9ac6bd41284e86f0199eba0e1d7ad3703d04e095b0c8ae8ccf850b32365acn/aCobaltStrike
2020-11-11n/aexe 10f982f456d963b82655b03b59a4ea4877832899067e14c96990b809c5767b72n/aCobaltStrike
2020-11-11n/aexe e46873324ee44e0f0b2b3ea745abe5f1b7875189bc04d9abc86330620ab97c51n/aCobaltStrike
2020-11-11n/aexe 9db36c4d4f578a68ddbabcf25a2a3ba0a0e0cce2847f62da9ac4f8b5682ab745n/aCobaltStrike
2020-11-11n/aexe dbcb927d98301d49758b5a6e419e618acb92ecef3bef20c99374f5fde154eb1dn/aCobaltStrike
2020-11-11n/aexe 06a2955307b8c26009b441754df7d0c94d3a913b0644a3c8779f592648dd1a0cn/aCobaltStrike
2020-11-11n/aexe 0adcf0b5e5216f4ac6fe82d4e2c7e351845cfaf6717552aaa0c80d643ee9f2een/aCobaltStrike
2020-11-11n/aexe 777b4ad720e0c2982e161342e3cf77cb755875664f24131018b7df4d853fcd60n/aCobaltStrike
2020-11-11n/aexe 7566ae70559b61077911e17564dd470be33abcf8e725352f546a731af43e5297n/aCobaltStrike