URLhaus Database

You are currently viewing the URLhaus database entry for http://wmwifbajxxbcxmucxmlc.com/files/spam20.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:347004
URL: http://wmwifbajxxbcxmucxmlc.com/files/spam20.dll
URL Status:Offline
Host: wmwifbajxxbcxmucxmlc.com
Date added:2020-04-20 18:30:04 UTC
Last online:2020-04-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-04-20 18:32:04 UTC to abuse{at}selectel[dot]ru)
Takedown time:1 day, 20 hours, 3 minutes Poor (down since 2020-04-22 14:35:25 UTC)
Tags:dll ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-21n/aexe e89e8fc7aab6c9e178374c678f0f4cd5297669a282f93a418c4871da9c840a32Virustotal results 11.27% 
2020-04-21n/aexe 8b92cb61cd199e7261e98738095ea6c339721c0d5d15a9ae61eb2ed40de77000n/a 
2020-04-21n/aexe f45904a7d7590e47966727250bceff8bda7f8274072b8f46257f818a52f945f9n/a 
2020-04-20n/aexe 2f2670e8a7845cf300320415c6a16ffc34e662672f16d7cfcf5b911d088516d9n/aZLoader
2020-04-20n/aexe c55e3938e9c2c9d00235d8ed87a55adc18fa1c6377a9ee0fd6212916c67d0020Virustotal results 16.90%ZLoader