URLhaus Database

You are currently viewing the URLhaus database entry for https://skinfolabs.com/xmnps2t.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:887504
URL: https://skinfolabs.com/xmnps2t.zip
URL Status:Offline
Host: skinfolabs.com
Date added:2020-12-04 03:45:12 UTC
Last online:2021-01-05 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-04 03:46:26 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:1 month, 2 days, 7 hours, 32 minutes Bad (down since 2021-01-05 11:19:25 UTC)
Tags:dll Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-04n/adll ebe87cc844fd9875d411b5435f0ffee5e651be5ff011a306a09a6b5f3376c81en/aDridex
2020-12-04n/adll c96fa76a5147bf58b44c47fe42c9449da7494bf329c11e3e2792fdca8fff917eVirustotal results 30.43% Dridex