URLhaus Database

You are currently viewing the URLhaus database entry for https://nachoserrano.com/wp-content/themes/Divi/core/admin/css/pik.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:147272
URL: https://nachoserrano.com/wp-content/themes/Divi/core/admin/css/pik.zip
URL Status:Offline
Host: nachoserrano.com
Date added:2019-02-26 09:24:35 UTC
Last online:2019-07-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-02-26 09:28:13 UTC to iker{at}cubenode[dot]net)
Takedown time:4 months, 28 days, 20 hours, 27 minutes Bad (down since 2019-07-25 05:55:57 UTC)
Tags:RUS Troldesh link zipped-JS

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-27n/azip aa20d488973aee40db0019cc6560f9666a14347f2f3612332ae3b10efba0f829n/a 
2019-02-27n/azip b82d965d0f141f511b84768f48d9123bb9e0feb8bb9a4154fefc51a2fc0cf633n/a 
2019-02-27n/azip c6c1da3e3804b3e284bc514f408f99652f8c852b02871b16a03b422136225ab4n/a 
2019-02-26n/azip f232f223d41c48aec486c6f7c97c190c4feef625298daf3386a328555f748761n/a 
2019-02-26n/azip 32cca1764f99e5e949ecace6ef73d73b00f05e2ffad6dd0312129d33d219dd55n/a 
2019-02-26n/azip ef5bbe253927e357da0dd4dda107b3be56d18e27953cb4aa9332149088f0fcd8Virustotal results 29.31% 
2019-02-26n/azip 206fed7def10e135bf454acfc2ab899e776b6ba31bb3c973daf9f6f79d72e561n/a 
2019-02-26n/azip 9b20ffbc71bc15590de1117fd6aaefaf9022d1242107cb2e6ba1a59a9fcccd6bn/a 
2019-02-26n/azip d880212197a0b979dcabf78ad2f62ef67dfbf3afd34be1a5db3094d150810871n/a