URLhaus Database

You are currently viewing the URLhaus database entry for http://www.prorish.com/wp-content/plugins/maintenance/includes/fonts/M8kiSjNOkR.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:923577
URL: http://www.prorish.com/wp-content/plugins/maintenance/includes/fonts/M8kiSjNOkR.php
URL Status:Offline
Host: www.prorish.com
Date added:2020-12-16 18:33:04 UTC
Last online:2020-12-17 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: ffforward
Abuse complaint sent (?): Yes (2020-12-16 18:34:05 UTC to abuse{at}hostinger[dot]com)
Takedown time:6 hours, 10 minutes Good (down since 2020-12-17 00:44:28 UTC)
Tags:dll Dridex link php

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-17n/adll e312b1f89a07139da91d7c5e54566746396c76290502bc9bd63922d6f4afaf1en/a Dridex
2020-12-16n/adll 3b2b427251aca4677e68377c0e91356f0f2b49bba05b0e8f3e4d033e3e0b8f37n/a Dridex
2020-12-16n/adll 07038a2930b7dcc77c49f140b886e2b35971745764f154923769bf49b01f7916n/a Dridex
2020-12-16n/adll 3660611abce12ca74d44f1330deb115a4affe845c93ef921d3124c1770df5123n/a Dridex
2020-12-16n/adll 12fec3e176c633fe4182e072aa80e5e360b61364e2ad9722f41a93d6cc2648c9n/a Dridex
2020-12-16n/adll 49a72fcc160c2e2f7aa7a18b35e104b1528a93177e26bbf9b5ec388f8db2076dn/a Dridex
2020-12-16n/adll 139d34130498350e3558463d8c2ed1e08b1b6186c0793e15ab38f3b9130948edn/a Dridex
2020-12-16n/adll 84b3d1a533f7ea8507483306e2006e8b929d6543cdbb171230bd0092ec753f21n/a Dridex
2020-12-16n/adll f23af41066c9994f133186c912ce12cbc993af7cd661618f955e35ebf38c5380n/a Dridex
2020-12-16n/adll 4539c7e67a13cac9b192bc12bd347fa55768e2c302b07f7a048173ae787ff56dn/a Dridex
2020-12-16n/adll 57c85bae5b0bed1a16cdd9048a80126a8f1f4ee7968524922c13b7ff30a00b26n/a Dridex