URLhaus Database

You are currently viewing the URLhaus database entry for http://mobile-fueldrain.co.uk/sport/rockstar.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:339486
URL: http://mobile-fueldrain.co.uk/sport/rockstar.php
URL Status:Offline
Host: mobile-fueldrain.co.uk
Date added:2020-04-13 13:33:10 UTC
Last online:2020-04-13 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?):mail Yes (Ticket DCU002478305 created on 2020-04-13 13:34:05 UTC)
Takedown time:3 hours, 19 minutes Good (down since 2020-04-13 16:53:35 UTC)
Tags:exe Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-13239YASSPP1.exeexe d979a633b4c59b416997f1e3926273e31f56b68c217813a56ae5d3deff3814bfn/a TrickBot
2020-04-13304YASSPP1.exeexe 31374c09ed2fd78785e6e82850b4ab3cde011244f32aa98f238238df1584cda7n/a TrickBot
2020-04-13731YASSPP1.exeexe 5b42929b3ea6e3671d336309a35adff6767c66efb1aa2ff162d9daf1154f4119n/a 
2020-04-1349YASSPP1.exeexe 37d4f63c73dfbcdb5bb9795c2980a05231d35c27d17a2dd7a0b8215ade98ab45n/a TrickBot
2020-04-13933YASSPP1.exeexe 9294524378bba310b2bf22cd2ced2601c05e4fd2debe3a65e6d2e900fb0e89c5n/a TrickBot
2020-04-13630YASSPP1.exeexe 9ba7c20ab046437d4918c104c232bda87308b5c5e2b0d9f658870994105f72c2n/a TrickBot
2020-04-13927YASSPP1.exeexe 33c7be4a31ebdc3d483fa21f032c4ccef1037a83f9f3034343fc149ef86a341en/a TrickBot