URLhaus Database

You are currently viewing the URLhaus database entry for http://stdychnesqudusisabst.dns.navy/secure/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:969399
URL: http://stdychnesqudusisabst.dns.navy/secure/svchost.exe
URL Status:Offline
Host: stdychnesqudusisabst.dns.navy
Date added:2021-01-18 04:27:06 UTC
Last online:2021-01-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: gorimpthon
Abuse complaint sent (?): Yes (2021-01-18 04:28:02 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 9 hours, 23 minutes Poor (down since 2021-01-20 13:51:36 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-19n/aexe 5551c39b0838a38711babfe60b36dda8855791ce1512553858fbaff025d31122n/aFormbook
2021-01-19n/aexe b9a286880c70bf7b6b049c8be7b7b14d8318b6c38d04185eced4bc48795330ffn/aFormbook
2021-01-18n/aexe a38cbbb16b9dda3d7aebcdcd033a8f5e56f17257c060859a3cdd2e1a8bb27ab9n/aFormbook
2021-01-18n/aexe 90f3043c27c16f9ff2dfc53a027b053415ff9a20699086611bf57cfdbeafb41cn/aFormbook
2021-01-18n/aexe 083210286a8bfd2e1cbd05ae990725c8d41c4a6b3bdf71c8325b9cb11781a1aaVirustotal results 10.29% 
2021-01-18n/aexe b88d84be2994a05ac716dac99a689356d8c7ecbd541989a5339be403da909430Virustotal results 10.14%Formbook