URLhaus Database

You are currently viewing the URLhaus database entry for https://auditis.com.br/empa6t.rar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1859163
URL: https://auditis.com.br/empa6t.rar
URL Status:Offline
Host: auditis.com.br
Date added:2021-12-06 13:32:21 UTC
Last online:2021-12-06 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-12-06 19:00:39 UTC to abuse{at}lacnic[dot]net)
Takedown time:7 days, 0 hours, 20 minutes Bad (down since 2021-12-13 13:56:33 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-09n/adll 1c5e30070e77f86b009b0a70e465bd90a93f443b6f0cc067ec37d7b7d8672a51n/a Dridex
2021-12-09n/adll 61525a29b774cad1eb817c1902b1be88db0b843b1c150b9d98005e663b6e14c8n/a 
2021-12-08n/adll b25e35753be5be97d057410ce756b956ac80a31947d2e9cb64ec8bc49f4321e5n/a 
2021-12-08n/adll 9c38b2638f66ff2e218fd1db36990c84d59a8382148204d491fe9ffd9fdfab78n/a 
2021-12-07n/adll 94496a541a8352674986f82be278c0a62a1ac53b1750cb03f3b9d15199fe2b5cn/a 
2021-12-07n/adll 00c6cb0d5553c0e4d1c081c9f173cab58dc344d236b7f372308f83b98fac9b18n/a 
2021-12-06n/adll 4cf90ed4044d8025261e4740f1b9a98ed5d2c63d9bd9758257bf0881b2e28acaVirustotal results 22.58%Dridex
2021-12-06n/adll d0681c030a51811edc6f19b6cc418043ef928e251c681cdf75a05949f932340bn/aDridex