URLhaus Database

You are currently viewing the URLhaus database entry for http://www.zichabowling.com/update.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:9692
URL: http://www.zichabowling.com/update.php
URL Status:Offline
Host: www.zichabowling.com
Date added:2018-05-11 13:50:58 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2018-06-11 10:39:26 UTC to abuse{at}godaddy[dot]com)
Tags:GandCrab link Ransomware Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-171.pdfexe 8972995f2d87fb2e027ed836cf6a75bc77f1b8f8109b9937dbe9fd1f16609802Virustotal results 39.71% Ransomware.GandCrab
2018-06-161.pdfexe 9e9d8dd690d9abe0afa9455bef0e830d6996b49f628916b15d9483ec969a9c22Virustotal results 41.18% Ransomware.GandCrab
2018-06-151.pdfexe 58dac4bd0dfab57f2f8b990ec693903e697707b11ce9dcdbda01df96a5fa0f4dVirustotal results 48.53% Ransomware.GandCrab
2018-06-141.pdfexe 9f0fab3fbaae16e3ae7669aa4d1ab580dc56f56f14aa2c91badc9ea05fecfe75Virustotal results 47.06% 
2018-06-131.pdfexe fca64d5f8b3dd59ee7c1b60ae8ba42491aa3d686f50a44b6a7626e4c0612c5abVirustotal results 48.53% Ransomware.GandCrab
2018-06-121.pdfexe 4064053d7278a243f8805e7b7f6024e93ea12eb7501eddeb1090137f843b5ec2Virustotal results 44.12% Ransomware.GandCrab
2018-06-121.pdfexe 631ba5cc0d8eb1ad7e31b2688b390be6a4d871501d9bc0a4a37c4e2bf9c615c1Virustotal results 36.76% Ransomware.GandCrab
2018-06-111.pdfexe b9a5f6188b2113bf79190442700d6f20630756e1d82a541739edb012167301a7Virustotal results 40.30% 
2018-06-101.pdfexe 18299f847264c75d9f1e4474b96ad8d5b4ad5500248e55b7b2e1faf204a1967fVirustotal results 41.79% Ransomware.GandCrab
2018-06-091.pdfexe dc0b210e73f1fdb78a7b881b0c73a998e4e48c91e3a4d19188d5fdf091a82f34Virustotal results 43.28% Ransomware.GandCrab
2018-06-031.pdfexe c2d0c6d2d830ebcc829cc51c33a16a532d7c1fb64327559eadbd7461aaac2436Virustotal results 43.08% Ransomware.GandCrab
2018-06-021.pdfexe f6c56fe100a6aec4cad6cd5cb29b1044b1a8cbd730942bb6e6bc2a8a16331d91Virustotal results 32.31% Ransomware.GandCrab
2018-05-301.pdfexe 7ef3f365afe7d111e278a3e67bb77522d88502929e09cc0022d4fe7fbd19f37fVirustotal results 35.38% Ransomware.GandCrab
2018-05-161.pdfexe b770d920568c46459510861109956c60c21f877fe14b3e686cd6716e6133f312Virustotal results 45.45% Ransomware.GandCrab
2018-05-151.pdfexe 79ea45b1141089ca6ea7b8dc59cf7f44912982c7e0f890c15a577528f9d657dbVirustotal results 30.30% Ransomware.GandCrab
2018-05-11n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00%