URLhaus Database

You are currently viewing the URLhaus database entry for https://faog.org.hk/scanner/overwatch.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:339716
URL: https://faog.org.hk/scanner/overwatch.php
URL Status:Offline
Host: faog.org.hk
Date added:2020-04-13 18:42:11 UTC
Last online:2020-04-13 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-04-13 18:44:02 UTC to abuse{at}sgc[dot]hk)
Takedown time:3 hours, 46 minutes Good (down since 2020-04-13 22:30:42 UTC)
Tags:exe Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-134090dh7dhnx76s.exeexe 34ae344b732156af5b8b90e910567dda1e1df99b8d1e89b9780360ac4a30bdc6n/a TrickBot
2020-04-133180dh7dhnx76s.exeexe b9616a042c7e27ce189111fe064be6ce31895b2a813dc6f57f5060e2533f61e3n/a TrickBot
2020-04-132150dh7dhnx76s.exeexe 207ccb918cbb3ef4b6190f58b5aed67f9e45ca25c550cdb0abe8f8bb86d6d1aaVirustotal results 18.84% 
2020-04-134620dh7dhnx76s.exeexe 34e75d0bbd3e7eddff273680dd070f2f28af4797be1ba13bd46fb04ddd3202e3n/a 
2020-04-13400dh7dhnx76s.exeexe c50aa9b8c9d09a35fb1501d693b137e8e39dad33ddac4af847b263234d6570ean/a TrickBot
2020-04-132630dh7dhnx76s.exeexe 55e63894ec39083d618099a9763b9f57c4adc9a00c590db9ce1d285731effd02n/a 
2020-04-134590dh7dhnx76s.exeexe 3cd6109fb55980d399ff9a35e8d748e2ff0e0ec23281833edfd9aa344ff3bb94n/a TrickBot
2020-04-133100dh7dhnx76s.exeexe 271f94e3ed1e305ebe0a16b8695f471994304baee6f6c6f8812b7e0224063590n/a TrickBot
2020-04-134794345.exeexe 03dd6fef9abc5f9de90cf6f6465685a322bfe52d2958c654fe439848f94cc066n/a TrickBot
2020-04-135894345.exeexe 416434b83c347aff0a0ac62dcf8bb9b06888e2e31c71225a67759345603efaa0n/a 
2020-04-133964345.exeexe 3ed94a494797036bc420f3a4c3e253f8d755de71790f293d72f90ff214577e1an/a TrickBot
2020-04-133114345.exeexe f5cccfb937c0b8deebbf6cfc93ab5fe5c0a320b5a029e67839bb63d914eee490n/a TrickBot
2020-04-137934345.exeexe 58e9ee2523316a5a603f335c2fcd9f15ddf7075f8ead4fa1dbf4a7194d1609c3n/a 
2020-04-135194345.exeexe c5f4687f3077bca194d64f56b1e8e224825e701cf400848bde9b231b8b98c4acn/a TrickBot