URLhaus Database

You are currently viewing the URLhaus database entry for https://beltmexico.com/mgy9cg.tar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1674091
URL: https://beltmexico.com/mgy9cg.tar
URL Status:Offline
Host: beltmexico.com
Date added:2021-10-13 13:15:10 UTC
Last online:2021-10-27 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2021-10-13 13:19:16 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:14 days, 2 hours, 7 minutes Bad (down since 2021-10-27 15:26:44 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-14n/adll 5ce136190cb03f90d36d8dfeaae3e008a0a59415d081eb7b5be6802bcc44ba7bn/a Dridex
2021-10-14n/adll d759de9c016724326b323020c2201cfc633091bf7f104546634f64f801d26b1cn/a Dridex
2021-10-14n/adll d27f8c44bf5a82d98356fba379662d35b57cac933d9601f40e7a6854b1a2f9f5Virustotal results 18.18% Dridex
2021-10-13n/adll 43478f6b0e81549139ea3a5fd8f93194e57137bf9eba1ae1dfd9867286fb2983n/a Dridex
2021-10-13n/adll 8a47bb3a1987425ac99f81c7a307a30a22f6200782dec8b3cbf2ce825d322c39n/a Dridex
2021-10-13n/adll 426b5c4332e09b331eeabd7a4338c58a275fc0a6d99547a27b4c3e5c47182c95Virustotal results 9.23% Dridex
2021-10-13n/adll 7ab24453e040b90ec8d8389737ca6968a35ec24a28e494b97eb9eb770c90e8b2n/a Dridex
2021-10-13n/adll 7d938aefd1e3971b1b135badfae052ea71a3be5b0b9a74756717702fcc886e1dn/a Dridex
2021-10-13n/adll 3fd6a0b667270f85b4d929748b6b32d1ecb65d01fc0e3cec4bbc025452530f07n/aDridex