URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xaidol.com/update.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:10030
URL: http://www.xaidol.com/update.php
URL Status:Offline
Host: www.xaidol.com
Date added:2018-05-15 06:39:38 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2018-06-12 07:25:38 UTC to ip{at}cnispgroup[dot]com)
Tags:AgentTesla link GandCrab link Loki link Ransomware Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-151.pdfexe 7e1a56698fc2de587002a6b33fb974ce8a976091fb2f645c26cb9c309e77b620Virustotal results 42.65% Ransomware.GandCrab
2018-06-141.pdfexe a69d0a93747e86d93e1531ab649ea9623b4985eb063290fce7e999d10241ffddVirustotal results 38.81% Ransomware.GandCrab
2018-06-141.pdfexe a29444c8a7f3fbcdfba53713cb225e912af4153f55ed684cb1cd88cb36793dc4Virustotal results 39.71% 
2018-06-131.pdfexe b76ac57e039acf89fe1d2ddb4b6db8e8a7eb1775f04216f040941f946d238ff0n/a Ransomware.GandCrab
2018-06-131.pdfexe 1e233b9903247a066e5039722df9ec22931d82282de083e7ff648fb0542b01d6n/a Ransomware.GandCrab
2018-06-131.pdfexe 88a6597fae59a940c0a0d54a914ef1e47ff13b3dec796920053ba2a9bd3719cfVirustotal results 37.68% Ransomware.GandCrab
2018-06-121.pdfexe 41b5e623939fabff5a9022fa72f6ab93a3b35c38be67506afea7a236593a16c2Virustotal results 33.82% Ransomware.GandCrab
2018-06-121.pdfexe fb96ee08822e6f7f3e1c607217c8cd471fb06fdd7d523baeb3a946b0fef5e971n/a Loki
2018-06-121.pdfexe 631ba5cc0d8eb1ad7e31b2688b390be6a4d871501d9bc0a4a37c4e2bf9c615c1n/a Ransomware.GandCrab
2018-06-121.pdfexe d46c7bc70ee391640720bfc4461dccb4d057f30a9c1a14133b5dac1f781d40cdn/a Ransomware.GandCrab
2018-06-121.pdfexe aaf3c5dd4fcc168954f6feeb407e6997abb2df8ca1f6f268261bb3ad726e5ae5Virustotal results 38.24% Ransomware.GandCrab
2018-06-111.pdfexe ef9c5e300591d7f96c2c6e4c339a20e443f63c53d6bd2c75b1e67e560b257138Virustotal results 39.71% AgentTesla
2018-06-031.pdfexe 514b83d39510c7df24e98e598edb56d4e9090202e594960e6e61296e96c05ba5n/a Ransomware.GandCrab
2018-05-17n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-05-161.pdfexe d2f851fd60e85be31a5c5015c1cab7021941a09dd274682124d85abaff49f641Virustotal results 34.38% Ransomware.GandCrab