URLhaus Database

You are currently viewing the URLhaus database entry for https://proteinsupplementexporter.com/rlpsrwkf.rar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1098419
URL: https://proteinsupplementexporter.com/rlpsrwkf.rar
URL Status:Offline
Host: proteinsupplementexporter.com
Date added:2021-03-29 14:03:15 UTC
Last online:2021-03-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2021-03-29 14:04:38 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:16 hours, 28 minutes Good (down since 2021-03-30 06:33:27 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-30n/adll 0f34e1cb392c58a5885e73b1d1411efa7140ce6eb20ea39bbf4888d9e531d122n/aDridex
2021-03-29n/adll 3dca4ce0016f3996b0ac8c3d1ede6e4ee00a1ad8366fb1ed0514b24ff97c8589n/aDridex
2021-03-29n/adll b3a7004a8c20680b140a68137ae14ddcb6046857cba5a2ec66cbeee0a6f69f02n/aDridex
2021-03-29n/adll 1c59466ebeb76f89beca6ada657b94b9db51873b427a6e7fad65626f8f317818Virustotal results 8.96%Dridex
2021-03-29n/adll 41a9eb40e9c6b0b3e99c33f510aa4ba2cc4306e09df01c47e623b120c8e2a997n/aDridex
2021-03-29n/adll abce3c4bd1ffb97a83e060bdb4da1f3e983875d29863fbd4e398203978bb2321Virustotal results 9.09%Dridex
2021-03-29n/adll f9cbd63dfa11a2994f05945f9efefb9ce3d5c49942e68715ee738cf345a2b1f0Virustotal results 10.29%Dridex