URLhaus Database

You are currently viewing the URLhaus database entry for https://ziengineeringco.com/project-arab-contracting/css/dAHBzO4XG.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1121351
URL: https://ziengineeringco.com/project-arab-contracting/css/dAHBzO4XG.php
URL Status:Offline
Host: ziengineeringco.com
Date added:2021-04-15 14:01:05 UTC
Last online:2021-06-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-04-29 19:31:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 month, 3 days, 1 hours, 49 minutes Bad (down since 2021-06-01 21:20:40 UTC)
Tags:Dridex link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-01n/adll 792b775aca2937dc6e6ca704605f94e97380127d54197957ec22201a8c29c271n/a Dridex
2021-06-01n/adll 888f84db8e8133627223259b42bc6664f3691a527f2cb45811a0d9b7db786072n/a Dridex
2021-05-09n/adll c98664734635d644baeaa754e8690388650d4f7553e715247e6b9779925114aen/a Dridex
2021-05-09n/adll 8b3204d11747310d7fb35b5421fb1392439cca1d4289c02b4085785a34d03b78n/a Dridex
2021-05-09n/adll cc83d71e452fc22cbdbe6570dae444efe11b11438b58d6b4e92c397e888a50acn/a Dridex
2021-05-09n/adll 06460dcbbb053e6ca8011332499e0e5671c4ce260441d1e39211559ad52c6632n/a Dridex
2021-04-29n/adll 750976b883ad7f6efb02af5a1c8fa8cab209c9178371c0db6622dfd3006f52a7n/a Dridex