URLhaus Database

You are currently viewing the URLhaus database entry for http://waterdamagerestorationashburn.com/ABU/PUL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:168813
URL: http://waterdamagerestorationashburn.com/ABU/PUL.exe
URL Status:Offline
Host: waterdamagerestorationashburn.com
Date added:2019-03-30 00:54:16 UTC
Last online:2019-04-10 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?):mail Yes (Ticket DCU001147396 created on 2019-03-30 00:56:06 UTC)
Takedown time:11 days, 20 hours, 3 minutes Bad (down since 2019-04-10 20:59:16 UTC)
Tags:exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-02n/aexe 2bb3fd7439b52cd77e5b0439b10b9d8bb93a09c44c218c819816e3096525ac70n/a NanoCore
2019-04-01n/aexe 78cc1797b2972ef977797e52447a9b2a84353b0adbac0347238c9496c16b293an/a NanoCore
2019-04-01n/aexe de69e12e13b24a722dbffe69669c5d17cdf7d186d59dc8527e821dba8cb431e4n/a NanoCore
2019-03-31n/aexe 6d163a83239cb9e1a3906c129f9081cefc9cd7d9d6f3880c223ed0b9179e59fbn/a NanoCore
2019-03-31n/aexe 4acdf9ad8c28f43ca372df805544809ff1c268a02074a656f5447da1704f2dd7Virustotal results 15.38% NanoCore
2019-03-30n/aexe 6c7955e1370ca9b8e4d712706b6aed2a2fd210d4f630387d84eb64a9878ddcddVirustotal results 39.06% NanoCore