URLhaus Database

You are currently viewing the URLhaus database entry for http://fumukav.com/web.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2284576
URL: http://fumukav.com/web.dll
URL Status:Offline
Host: fumukav.com
Date added:2022-08-30 06:25:06 UTC
Last online:2022-09-01 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-30 06:26:06 UTC to abuse{at}combahton[dot]net)
Takedown time:1 day, 18 hours, 15 minutes Poor (down since 2022-09-01 00:41:26 UTC)
Tags:CobaltStrike link dll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-31n/adll 08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0en/aCobaltStrike
2022-08-30n/adll 0947c2c8f5784152e657b85e88eefc11c6a07acf0da3528e52299d16a3d7bfd6n/a 
2022-08-30n/adll b3b3121d08c2ef4e38b5b67275314a0405eee50b982174d5745adea45a8f3066Virustotal results 44.93%CobaltStrike