URLhaus Database

You are currently viewing the URLhaus database entry for https://lamesuspendue.swayb.com/pxxnmie14.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:585776
URL: https://lamesuspendue.swayb.com/pxxnmie14.zip
URL Status:Offline
Host: lamesuspendue.swayb.com
Date added:2020-09-21 12:11:04 UTC
Last online:2020-09-30 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2020-09-21 12:12:07 UTC to abuse{at}online[dot]net)
Takedown time:8 days, 20 hours, 27 minutes Bad (down since 2020-09-30 08:39:59 UTC)
Tags:DLL. Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22n/adll df5bad6333c3fd1772caaacea0cd31df1d7260c67b590d5cccb90ffaebcc6876n/a 
2020-09-22n/adll ca59edc0f721f34fa3178168dcc138947f1370d1672a9653e42eec0327f2ec6an/aDridex
2020-09-22n/adll 8f41170849381dadf71a629f8aef96e1d4ce86adb440303eb562a63d3b064c53n/a 
2020-09-21n/adll 6fc93afff036f672f73751d77ca592b99629109723bf4c2c0758b499afefb352n/a 
2020-09-21n/adll 1db38d773d052e456749bb5fe1fd6ef045dedd30b8b1a0ae42bb62c26e9a2f18n/aDridex
2020-09-21n/adll 2d7c7b9472f1f4bb2f678822f16e8575971574ba763bd9e98fdb7d8b2a8f5d2en/aDridex