URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dayzhifupay.com/%E5%AF%86%E7%A0%81%E4%BF%9D%E6%8A%A4%E5%8D%87%E7%BA%A7.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1394170
URL: http://www.dayzhifupay.com/%E5%AF%86%E7%A0%81%E4%BF%9D%E6%8A%A4%E5%8D%87%E7%BA%A7.bat
URL Status:Offline
Host: www.dayzhifupay.com
Date added:2021-06-24 08:57:09 UTC
Last online:2021-06-30 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-24 08:58:04 UTC to info{at}ping[dot]com[dot]hk)
Takedown time:6 days, 2 hours, 36 minutes Bad (down since 2021-06-30 11:34:28 UTC)
Tags:32 exe younglotus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-30n/aexe 5fc335f79202263e7e68942ffc5f14d705db9caf44c09255ba142f5489a28155n/aYoungLotus
2021-06-29n/aexe 38590535738c42247dc06b18dc9bf011859942183a2de27e2f0fa2400bfa38d8n/aYoungLotus
2021-06-29n/aexe 74dbeb55a591b4be7e7bfb52bdf1c09cb9de245ec9f43b12f40a86f1ba39883fn/a 
2021-06-25n/aexe 0e4c2040ee56cf81df3334e99fb2e419e9ed81a3c9d47bd8f57bb8a95a927baan/aYoungLotus
2021-06-24n/aexe cb1b5642d56aedff09b5eb8368bf54d2ec8a710de5f7cfcfb7fdc6148619dfd8n/aYoungLotus
2021-06-24n/aexe 04a7caa6cb7a45a1251f28f4ad9479e78f0fed395851c97729d30cc0490062e3Virustotal results 31.25%YoungLotus