URLhaus Database

You are currently viewing the URLhaus database entry for http://alphasheild.com/metalf.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434628
URL: http://alphasheild.com/metalf.php
URL Status:Offline
Host: alphasheild.com
Date added:2020-08-17 13:20:14 UTC
Last online:2020-08-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2020-08-17 13:22:02 UTC to khatamband{at}gmail[dot]com)
Takedown time:5 days, 0 hours, 15 minutes Bad (down since 2020-08-22 13:37:44 UTC)
Tags:Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18414havymetal.exeexe 53827c2bc5a14548fc69edfab8e05aaeae25bc6f7c3127e55a139a04cf47e7beVirustotal results 13.04% TrickBot
2020-08-18176havymetal.exeexe 99dc1e6c7b821f9931a796496e2daf6fd4b6d71112fbe4db628346500754ff33Virustotal results 17.14% TrickBot
2020-08-18400havymetal.exeexe dc3e693b38502748bd4f72193705fbbc87bec00d38f62353f0d86079bea7e527n/a TrickBot
2020-08-18493havymetal.exeexe c512b38e476dada9b7b00d34625c8d543fa927068893482d8f521cddf2aadaa6Virustotal results 12.86% TrickBot
2020-08-17489havymetal.exeexe ef0378180ee06c4ea1ec113e9a3a81c528c958e2ba57d820f1e0b79839931192Virustotal results 15.94% 
2020-08-17215havymetal.exeexe 83e8b4e8bfda13e8c079c87624bfe25808cc9aa4b74b00b6543f9c0f11984242n/a TrickBot
2020-08-1718havymetal.exeexe c71ab925c9e567f64d8229d912b8380f302dab3648f51b0e8284ebef0504d1feVirustotal results 13.43% TrickBot
2020-08-17453havymetal.exeexe 9bf3b7bc3edb97d5100813d5552ef3d3f30c733c19d73088a557c7c35e41b91fVirustotal results 13.24% TrickBot
2020-08-1726havymetal.exeexe a3b1da76ef8f66bbba22d9c6af1f271737c8430ad18aea981ea54dfd913bb345n/a 
2020-08-171havymetal.exeexe 85125d31afb7e4e43c181645e084eb414ca27d0f174b19cf9fe6bed39b8f8721n/a 
2020-08-17294havymetal.exeexe 671c9537d12d7d62425dcd7260a20cd4b360403a9ac96c4c75670e3bd07ba21an/a 
2020-08-1716havymetal.exeexe c35df2c45016aac3807290fd0a5fc5ccf2f11cd9ff8aa90cf9185fa1e1fa0632Virustotal results 14.29%TrickBot
2020-08-1723havymetal.exeexe 1f281fc8459610058e7a884b51fb73347730853759b4acdb5dbb9d8dcce0868cn/a 
2020-08-17157havymetal.exeexe 8bd6232899bb78f16deaa1b35ea040027c74c7f0d7028cd5b35507bbf79eca97Virustotal results 14.93% TrickBot
2020-08-17258havymetal.exeexe 9ce8e43223dbe77ae6eb93c9b52c4167324de5af4dfefc8dc769364ac0c06d73Virustotal results 16.18% TrickBot
2020-08-17havymetal.exeexe cb14cfde1a13ff2af4e59b91ed9dca3bb0e024dd24cd671271fe98da8dd16b48n/a TrickBot
2020-08-1724havymetal.exeexe 4ae7c82b0152b375a4e1279d7df7ee6ebd44f5e3d6ecbfe53b81d3044ba25bacn/a TrickBot