URLhaus Database

You are currently viewing the URLhaus database entry for http://appliedlogisticalconcepts.com/wp-content/plugins/rounding-master/demo-importer/demo/MRbjhZoUav.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:959198
URL: http://appliedlogisticalconcepts.com/wp-content/plugins/rounding-master/demo-importer/demo/MRbjhZoUav.php
URL Status:Offline
Host: appliedlogisticalconcepts.com
Date added:2021-01-13 23:18:11 UTC
Last online:2021-01-20 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003246778 created on 2021-01-13 23:20:17 UTC)
Takedown time:6 days, 10 hours, 13 minutes Bad (down since 2021-01-20 09:34:15 UTC)
Tags:dll Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-19n/adll 803072d2f1e6a69c5dfa88fddbd71122d702c71b423320c569c73a0a53c131efn/aDridex
2021-01-18n/adll 1d5d1759d2c30ae4260bec6046d5cb2e5a74a98ca5f25e7c3ff68cc86b0d9eban/aDridex
2021-01-17n/adll 92da9dda75e956409c5ee6ddeb9addc967c2adbda6a7214e1f28d8a9209b477an/a Dridex
2021-01-16n/adll d1f9df0adcda74ca5657d4d8e1ece82b50d0a714f418594e6c1c4219f1134443n/a Dridex
2021-01-15n/adll 440f4c068e7beb15c506c7a206775b007828b41e16ca479e22d6ea25ec65bbb4n/aDridex
2021-01-14n/adll b1e064769bb6ffea14c8f68a062f6861731876834ee420ecfc360da9ac833aa8n/aDridex
2021-01-13n/adll ef4eaf2bdc7ca32b9bc5c11c4855e07c4b35ba6f94d5307cfb61aa4ff3c63859Virustotal results 22.58%Dridex