URLhaus Database

You are currently viewing the URLhaus database entry for http://march262020.com/files/april8.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:337196
URL: http://march262020.com/files/april8.dll
URL Status:Offline
Host: march262020.com
Date added:2020-04-09 06:59:05 UTC
Last online:2020-04-10 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Jouliok
Abuse complaint sent (?): Yes (2020-04-09 07:00:04 UTC to ipas{at}cnnic[dot]cn)
Takedown time:21 hours, 17 minutes Good (down since 2020-04-10 04:17:09 UTC)
Tags:dll terdot link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-09n/aexe e3c48c72d0d090ac01bff8bf6d54c08a6fedcda2e527d424d6f64a70016d2ba6Virustotal results 17.14% 
2020-04-09n/aexe e4601ce15ad7bca4617ad033f129a5d507f8e55b979c97a78cf31a6f501cb046n/aZLoader
2020-04-09n/aexe c44e8d9dba3b4a4cc835b460e69d336347fd3fbfb67621d7cd6e8723976607cen/aZLoader
2020-04-09n/aexe f27183fd7586c6eaca1f6aaed3a7c3c6e52894e23b9656c3953318a85bbbec5dn/aZLoader
2020-04-09n/aexe 69b37a5b3044cb14a9fc32440212f242e52f657b93306f4b90cccc3087ed4773Virustotal results 20.29%ZLoader