URLhaus Database

You are currently viewing the URLhaus database entry for http://ppca.org.pk/tug88v.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:977490
URL: http://ppca.org.pk/tug88v.zip
URL Status:Offline
Host: ppca.org.pk
Date added:2021-01-25 15:43:09 UTC
Last online:2021-01-26 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?):mail Yes (Ticket DCU003276596 created on 2021-01-25 15:44:06 UTC)
Takedown time:12 hours, 46 minutes Good (down since 2021-01-26 04:30:18 UTC)
Tags:dll Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-25n/adll 5f5bea792adc24979fde02125541d92934b19de7590ec132f26fa7c8e8ea97c5n/a 
2021-01-25n/adll c8d896b40041c535bc5d3bc92ada108bfcee81428f2642c96f329b134b00050an/a 
2021-01-25n/adll 082428545643de9e923f69545cb1982a73bccc7a4e04842b292cb0fe27ac547aVirustotal results 10.14%Dridex
2021-01-25n/adll 1d25971fb74ce8abebeedc3b06d7237b0cdf043e0c362425d95a08f158ae94a4Virustotal results 7.25% Dridex
2021-01-25n/adll 0b3e6ada39214664cac30a55a1502a76f040b23b569a205504369372c9a36c8an/aDridex
2021-01-25n/adll f835d874ae6f9f27f1cbb390f419375151846539c2b3b2e8b60e353ff3f62ab8Virustotal results 5.80% Dridex
2021-01-25n/adll c965cd1c5dedab70ddfcf4d4be10884c717b1f7083b3992362cf88faa4f502een/aDridex