URLhaus Database

You are currently viewing the URLhaus database entry for http://mendezplumbingservicellc.com/101.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2260250
URL: http://mendezplumbingservicellc.com/101.exe
URL Status:Offline
Host: mendezplumbingservicellc.com
Date added:2022-07-22 20:14:11 UTC
Last online:2023-07-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-10 20:07:06 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:11 months, 23 days, 2 hours, 39 minutes Bad (down since 2023-07-10 22:54:45 UTC)
Tags:bitrat link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-08n/aexe dd7240be9d2cec023cca6ce1ef5619bb09fa9152207d5c439db787dfec0f232fn/a BitRAT
2022-09-06n/aexe 7c0b4d31a4d7e4211aa85206f68534b32e7e28f72164405a5cfae80ba9ca7a86n/aBitRAT
2022-09-03n/aexe 6213bfa0a3636254f2ea4874cd88be53b0daf9eeebc2a9d7ce1f34e7b2648751n/aBitRAT
2022-08-31n/aexe 15caebb19901c4f8a5e1797acf58bf058736ddf2ba5c260c67ea698332a63afbn/aBitRAT
2022-08-06n/aexe 276bbfa2e086f6c29165e2a90cd92a0d81ef0ed3afb7409c87eaef2c267d3b62n/a 
2022-08-05n/aexe 831a64fd26798b2bd340de75bb5098635294d7f90b502da05fad2d1c7f17292dn/aBitRAT
2022-08-04n/aexe 8eded7414f5fc061aa2726317092931c361f3fea022c5041ff4bf24f4b201b01n/a 
2022-08-02n/aexe 82a01540546ff4201dd98d45d0b7cfa5a56a00485add894e6b493afc23132e9an/aBitRAT
2022-07-22n/aexe 902db07687a97742aa5aee6a87347a01d451939de8f022420438c73e86f96ad1n/aBitRAT