URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xn--12c3bbfl6bxf7a4e8cydd.com/update.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:10037
URL: http://www.xn--12c3bbfl6bxf7a4e8cydd.com/update.php
URL Status:Offline
Host: www.ท่อตันภูเก็ต.com
Date added:2018-05-15 08:27:41 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2018-06-12 06:30:42 UTC to noc{at}proen[dot]co[dot]th)
Tags:Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-05-17n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-05-171.pdfexe 70b2ad601664d79c07d96071f16e07aa637b380554fe5ff131e0b739bc68f82fVirustotal results 37.88% Ransomware.GandCrab
2018-05-161.pdfexe d2f851fd60e85be31a5c5015c1cab7021941a09dd274682124d85abaff49f641Virustotal results 34.38% Ransomware.GandCrab
2018-05-161.pdfexe 1350d7e63c71391b1315ccd5e6d64fd47b05a4b0daffc26d25482340b645ad84Virustotal results 33.33% Ransomware.GandCrab
2018-05-161.pdfexe e804fe8fe0573df48218d70c19e21145d504da5ed3e3e6100442e3b52996c3b5Virustotal results 31.82% Ransomware.GandCrab
2018-05-161.pdfexe 4dfe18b3f86e0435ac138845e74b63243d58ff9dc4210cc1d80e9508318fc6ccVirustotal results 34.85% Ransomware.GandCrab
2018-05-161.pdfexe fe26b3e32dd87960bb9b6081e49f618fe85b0a9593cc755a086284f2156d5b3bVirustotal results 36.36% Ransomware.GandCrab
2018-05-151.pdfexe d226e3be990a8ca772b121630200c24dca3bf19bbe5bcd4bc17ed2e9b34955edn/a Ransomware.GandCrab
2018-05-151.pdfexe a42057415aafb008dbde0367994084f98a23ac79d4429f580c4ec7f92774ac4eVirustotal results 22.73% Ransomware.GandCrab
2018-05-151.pdfexe 79ea45b1141089ca6ea7b8dc59cf7f44912982c7e0f890c15a577528f9d657dbVirustotal results 30.30% Ransomware.GandCrab