URLhaus Database

You are currently viewing the URLhaus database entry for http://droujinin.com/cgi-bin/pik.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:147369
URL: http://droujinin.com/cgi-bin/pik.zip
URL Status:Offline
Host: droujinin.com
Date added:2019-02-26 09:31:07 UTC
Last online:2019-03-06 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-02-26 09:32:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:8 days, 14 hours, 20 minutes Bad (down since 2019-03-06 23:53:00 UTC)
Tags:RUS Troldesh link zipped-JS

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-27n/azip 849a7f86fc56261758d0f2039e3ca29e3885802e8f1564881308793cae538929n/a 
2019-02-27n/azip 877fdb6ceb7648ab50428d170de75216926966eb9f109d94015d8760ab5c53f9n/a 
2019-02-27n/azip e1ebd4c46a2be1d2f81675281cc1b3c527ad123f93b9a8297724326d5777feafn/a 
2019-02-26n/azip 28acfd56750c5cb4633da7da6b725d7a8b02acede7f32ad056381c482683f1acn/a 
2019-02-26n/azip 53abe9a6e4db238567af7e3025ce321b539eda2d5a7dae97d9090dd64299ac94n/a 
2019-02-26n/azip 6964f24abd6c8530da300c4783c4a9632ae4b6574adc707c1e8bf19245afb947n/a 
2019-02-26n/azip cf37ea0039760a336e1a109b2dffbe5ce2e6fcbf74e2ac9f1808ab63cb252ef8n/a 
2019-02-26n/azip 9168d266a7797b70dcb9b0f6de8989053c31444b4ec1e65f3dfb34a91d2e3928n/a 
2019-02-26n/azip 8d8165a00b3634f37de6f5c01b45b0b6bf22a5838e9f5c22d44307a7a0ca02c7n/a