URLhaus Database

You are currently viewing the URLhaus database entry for http://playd.healthnlife.pk/ldms/7f3c2473d1e6.exe#sp_vid which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3206695
URL: http://playd.healthnlife.pk/ldms/7f3c2473d1e6.exe#sp_vid
URL Status:Offline
Host: playd.healthnlife.pk
Date added:2024-10-03 09:51:05 UTC
Last online:2024-10-04 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-03 09:52:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:23 hours, 9 minutes Good (down since 2024-10-04 09:01:23 UTC)
Tags:dropped-by-PrivateLoader Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe ddedf8bf0509656b2a6e02df085a1a76e60fdf174b232e6dd4695643385bbf6en/a 
2024-10-04n/aexe 8eabdfcfadad8ac12185a77ac647813b28be7d9d64939f70bd13a2e6b5e1f3fcn/a 
2024-10-04n/aexe 2b73ae13592508cc8ef29ef16b0a9be0d94b3bd5ecab6ed0093576e159c68db4n/a 
2024-10-03n/aexe dc66317c81a8afa7effe4a74d4b9fa74d1081fa26e13bac7bb0e01786cb6ba06n/a 
2024-10-03n/aexe 9688c766208957fed395338177b15a3b231a3b3966bcc7500ac556f1e04f7773n/a 
2024-10-03n/aexe 866ec52c5296cde6aa8dedd875299258c783a9c4a07f98851e6fd7c9367396dan/a 
2024-10-03n/aexe 859a8fdbc36d7244daf19cb58aa460ffd71585c73a341dfde786146f80000bfeVirustotal results 26.76% 
2024-10-03n/aexe 232c890d5bb7ecf69fc171813e593992d3e49539f7c0e2e9fa83129f5c47553an/aVidar