URLhaus Database

You are currently viewing the URLhaus database entry for https://tricommanagement.org/fonts/font-awesome-4.7.0/css/cbxCOgnfVV which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1372342
URL: https://tricommanagement.org/fonts/font-awesome-4.7.0/css/cbxCOgnfVV
URL Status:Offline
Host: tricommanagement.org
Date added:2021-06-17 07:42:07 UTC
Last online:2022-03-16 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: info_sec_ca
Abuse complaint sent (?): Yes (2021-06-17 07:43:05 UTC to abuse{at}amazonaws[dot]com)
Takedown time:9 months, 2 days, 3 hours, 32 minutes Bad (down since 2022-03-16 11:15:19 UTC)
Tags:CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-13n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2022-03-13n/aunknown 7a6837edc95157d66dd3bfec81ada8dbcf1601942b049da150e371b847eefea8n/a 
2021-06-17n/adll 407eed9aa2c05b67f0bbbcb87f73aac7952a468129f264ed2d42437f78df7b70n/a CobaltStrike
2021-06-17n/adll 434c246d2be81c0a28aea4b865656de223e083ce670581843cff4c67d66da0ccn/aCobaltStrike
2021-06-17n/adll c3163389f8926bb33178e27ad11af95395955da44380a4ffd84ef7f8af135c1en/aCobaltStrike