URLhaus Database

You are currently viewing the URLhaus database entry for http://playd.healthnlife.pk/ldms/9dd06d870941.exe#d15 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3208327
URL: http://playd.healthnlife.pk/ldms/9dd06d870941.exe#d15
URL Status:Offline
Host: playd.healthnlife.pk
Date added:2024-10-03 13:13:13 UTC
Last online:2024-10-04 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-10-03 13:14:08 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:20 hours, 38 minutes Good (down since 2024-10-04 09:52:44 UTC)
Tags:dropped-by-PrivateLoader Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-04n/aexe c7a9b126d27a142ad49c3b46591716348393efae2bf563df648701827bd7f80cn/aVidar
2024-10-04n/aexe 79ca49d6f16806e42b467c64d974b1dca360f8efb46de9a2b0eddbce98ed1391n/a 
2024-10-04n/aexe 9705faf02935de1ce8fa941d94d41f13aa59966f85150490d1d1fe1561aa9f9en/a 
2024-10-04n/aexe 9ad31484832e55f16e45c6f354516fbc17b9b89d18b92fd289eafac80c01eecdn/a 
2024-10-04n/aexe 65bb329fc87c4800eee894ac9ae8828b86145ae16f0d9aa436b8dfe2751ab8d8n/a 
2024-10-03n/aexe f473ea0af56a0eaf382791ce1c4c2ae13483bfabb11341d916cf4511d350efd1n/a 
2024-10-03n/aexe 20a196ec668c48ebea47bac535063ab5befcc83069c5516168d51adcbeff9344n/a 
2024-10-03n/aexe f5152e59ad8b12bd44dcd72b83d655d50d55b81b047e7bc585824907e6e4b5c1Virustotal results 27.78% 
2024-10-03n/aexe fa8e8dfb272f18daaece8b6ac3f9d6b16f9484764aff1005c9096909d75f760dn/aVidar