URLhaus Database

You are currently viewing the URLhaus database entry for http://indiaohc.com/file/n/schhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:810597
URL: http://indiaohc.com/file/n/schhost.exe
URL Status:Offline
Host: indiaohc.com
Date added:2020-11-12 13:10:04 UTC
Last online:2020-11-23 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-12 13:46:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:10 days, 15 hours, 37 minutes Bad (down since 2020-11-23 05:23:07 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-17n/aexe fc616c5cd59810cbfb8418141b2a652b92dd5163a8b9adfa54c79024916f17f2Virustotal results 30.99%Formbook
2020-11-15n/aexe 558c5ff8f9a54cbc67df9d042a6c4339a38da73f0c7ed688f601f0ab2317dfdfn/a 
2020-11-14n/aexe 3f4cad2de4aeefbfb460004d2def53d35d8b162cdd8a859cc503e6a04dcd38d8Virustotal results 20.29% 
2020-11-12n/aexe f773778f6eb4e9aa3ab3bd385409acd50081e57aed0e44bbda6308310e8c7316n/aFormbook
2020-11-12n/aexe 71fa0160ef98f5ebf3f957f156a5368e2010b831e5f5ee618d2e414c29625987Virustotal results 22.86%Formbook