URLhaus Database

You are currently viewing the URLhaus database entry for http://tool-api.elpix.de/files/pik.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:147380
URL: http://tool-api.elpix.de/files/pik.zip
URL Status:Offline
Host: tool-api.elpix.de
Date added:2019-02-26 09:31:20 UTC
Last online:2019-04-27 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-02-26 09:32:16 UTC to abuse{at}tops[dot]net)
Takedown time:2 months, 0 days, 4 hours, 31 minutes Bad (down since 2019-04-27 14:03:27 UTC)
Tags:RUS Troldesh link zipped-JS

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-27n/azip 8b6eece0776e2704a9f4b599556803bc734f7c57632940968de7c1e5f5404890n/a 
2019-02-27n/azip 4406c6cd36fecfe22ed6f0afa6fa9e201acd6194ed21ad7093bc9b13f2071887n/a 
2019-02-27n/azip e0001bba0b4af63106a3c493a7ba2cf94539ba87b70182d3003db8928f860266n/a 
2019-02-26n/azip c6e73a0864c84c876474f082875bfe3a4fc1ae0fea1525d6b15e7caa50a9e74eVirustotal results 32.76% 
2019-02-26n/azip bd2dd9c058c8183ed03dae29975a7cb58fa0c4a6530ba4d8883fc53c85de495fn/a 
2019-02-26n/azip 5aff826091c3e74598da176b8c9c7a02c30eb58bf0bdfc76e5ea35d242b1c5b3Virustotal results 28.33% 
2019-02-26n/azip 35aedce18fcdd2f341552df86f540b53b38248ef02814fa870fd1ec65fc11a88n/a 
2019-02-26n/azip b17063925e5278a0746f6d82ea43d19ad5ec46d5f3602bc11861cd59a6ab677fn/a