URLhaus Database

You are currently viewing the URLhaus database entry for https://yfo.yag.mybluehost.me/wp-content/uploads/2020/08/file1.cms which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1799907
URL: https://yfo.yag.mybluehost.me/wp-content/uploads/2020/08/file1.cms
URL Status:Offline
Host: yfo.yag.mybluehost.me
Date added:2021-11-18 18:27:11 UTC
Last online:2022-01-03 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2021-12-22 10:50:27 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 year, 10 month, 9 days, 1 hours, 58 minutes Bad (down since 2023-09-18 20:26:29 UTC)
Tags:IcedID link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-25n/adll b33a956476963ff5dd1fba448b5b2fc44bfab73e203e3833cdf04d3644eef1aan/a 
2022-04-25n/adll 375ec4130170dde1532ea4579d81c77b6646cc1957cdfc5e38ca4a091ec196c6n/a
2022-03-23n/adll 1034bc606a79bb63e9327d3f5fafd6b68054c4f7e07e69d2f17dce5e1331ba11n/a IcedID
2022-03-14n/adll a2b709699ae00ce73c04d2d422bf9e0108bb3041be2db1bb01e31074de4b73bcn/a 
2022-03-12n/adll 01ed407a1a1affc8b48de33afb3aca0b89e6ee426d62faf0585b256b909f31a3n/a 
2022-02-08n/adll b444f740cfdcc089b5b5e6a4a6ab13830d7a1ae68def76a2b01242c701f5428en/a
2022-02-07n/adll c391aff5321bbb74cd72d876062bd41f120cfeabb20d07b383ffdd76fadc4904n/a
2021-11-18n/adll d5a4fcb0e552cad22b1a907e874295b08e83d58bd83f9b4788c90aaad263cd87Virustotal results 6.15%IcedID