URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ningzhidata.com/download/IDG-NJCKV1.0-20200320.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:342066
URL: http://www.ningzhidata.com/download/IDG-NJCKV1.0-20200320.exe
URL Status:Offline
Host: www.ningzhidata.com
Date added:2020-04-17 08:54:30 UTC
Last online:2020-04-20 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-04-17 09:08:14 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:2 days, 14 hours, 58 minutes Poor (down since 2020-04-20 00:06:20 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-19n/aexe 5fb2fb4e2c9d8fe28ea224d82fb44f597ed5ff5ac68579a8cad9510b51d1ff23n/a Adware.Generic
2020-04-18n/aexe 437e4ca567281cd477f90580924f9c0efd6ff0a0ac3283c2c91a9e0cb6e8129fn/a Adware.Generic
2020-04-17n/aexe b1aca24370b1765a29c9004bef9551f5724bffc83d478dc023064d8a7e0d2924n/a Adware.Generic
2020-04-17n/aexe c5c5e59bb18bad1427714d0007b676e658d8e08faf5a0632ed88912f5816d525Virustotal results 26.39%GoldenSpy
2020-04-17n/aexe 1c0caabb8de15dd7c74c95e08a750c75a572739b7590437b67aa1f8de8154401n/a Adware.Generic