URLhaus Database

You are currently viewing the URLhaus database entry for http://playd.healthnlife.pk/ldms/04a4f32fae41.exe#d16 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3206698
URL: http://playd.healthnlife.pk/ldms/04a4f32fae41.exe#d16
URL Status:Offline
Host: playd.healthnlife.pk
Date added:2024-10-03 09:53:04 UTC
Last online:2024-10-04 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-03 11:11:09 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:23 hours, 36 minutes Good (down since 2024-10-04 10:48:08 UTC)
Tags:dropped-by-PrivateLoader encrypted

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe 700a463b3d99476bfc3b28f8a081f757dc8fedc8bae4d86c1e76a02e99bfef56n/a 
2024-10-04n/aexe 68364119472099b1b13fa55b161e20ff41a15db32ab70e77851a83fe25b2b565n/a 
2024-10-04n/aexe fa2b0f3184c7ff640218235954411b6844b3e2f05681b8d87971dc68275ec886n/a 
2024-10-04n/aexe 2d4bf0ef52091d73855bfa0e18ab623d114e07de32c8a67a7d0426d9f76b5a8fn/a 
2024-10-03n/aexe cb1e8020fb601b9154670126e32b2a9a2c8d15ac996458d8dd39c4a807170040n/a 
2024-10-03n/aexe 9ffb3ada874f8a5f58c6f5748e95662f4b09aeca06f0100fd40f82364e5cc30en/a 
2024-10-03n/aexe 8f25b1879c456fd6eb933b59e0cca8e802ebf84b94ca7dc019f47a34c6aca4e3n/a 
2024-10-03n/aexe db823ee90b3d026715cb6bc0a0ed8aa397ed1d25dd976a9aee7f60642505d2afn/a