URLhaus Database

You are currently viewing the URLhaus database entry for http://nkybcc.com/templates/jsn_decor_pro/backups/pik.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:147379
URL: http://nkybcc.com/templates/jsn_decor_pro/backups/pik.zip
URL Status:Offline
Host: nkybcc.com
Date added:2019-02-26 09:31:19 UTC
Last online:2019-03-01 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-02-26 09:32:35 UTC to abuse{at}a2hosting[dot]com)
Takedown time:3 days, 6 hours, 18 minutes Bad (down since 2019-03-01 15:51:02 UTC)
Tags:RUS Troldesh link zipped-JS

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-27n/azip 577f97a3e3e60f5bb5ad8f1c8569eeb33e248066bab686d9e5ba07d178b4f227n/a 
2019-02-27n/azip 866cf62d9d257f3d7a26587fd7991bab0c8774c7dee8f03852cba2cd48b97a25n/a 
2019-02-27n/azip 29dc6285d3ba8537edfc9193cd52881978b9d7b06d0e911c120f69975730581fn/a 
2019-02-26n/azip 880f6cc2fbf2ae21df7f1b28a40c9f9e54a1dcb23f5a4d1741eb8177367caa00n/a 
2019-02-26n/azip 2504589eec6c6a48066b7769561b6193bc8f579f0b4178da92a06c213c8cb0a0n/a 
2019-02-26n/azip fe1e14d033738a1d9b21b0ee0901119d4139d0629b38aec7838866c153a98288Virustotal results 29.31% 
2019-02-26n/azip f891666bcb8a17636eb1720ca5dadbb42655d4d3e65469b5803d9ed8923c17c7n/a 
2019-02-26n/azip 6df67e21d494a4b536b53ddce1bbadfda4e5ad3b9cebf4dccbf4371b67f7b96bn/a