URLhaus Database

You are currently viewing the URLhaus database entry for http://uscsmedicina.fdce.com.br/if9hgars.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:977849
URL: http://uscsmedicina.fdce.com.br/if9hgars.zip
URL Status:Offline
Host: uscsmedicina.fdce.com.br
Date added:2021-01-25 16:41:17 UTC
Last online:2021-01-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Myrtus0x0
Abuse complaint sent (?): Yes (2021-01-25 16:42:54 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 days, 17 hours, 4 minutes Bad (down since 2021-01-29 09:46:58 UTC)
Tags:Dridex link dropper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-26n/adll 26bf46b79aeb7775dbf7ccef58f5becb631ac14591ec9e1cdad6962600db5bc6n/aDridex
2021-01-26n/adll cc242ab99ab6100dcdc98f004f26041fdd5b67015630d73bff76b03a3d2d607fn/aDridex
2021-01-25n/adll f266da745f41e800d67215cf4f1da5c25acea3f0c0741bfa60c44ec047ada0een/a 
2021-01-25n/adll 98d34bcabc9744d79000ed1391ead17a2b3d8bcd4f12999282cce1cd8dcfc059n/a 
2021-01-25n/adll 082428545643de9e923f69545cb1982a73bccc7a4e04842b292cb0fe27ac547an/aDridex
2021-01-25n/adll bac8f79f5058d93c00717a55e471ebdd374679fca18ba4be874a1a7ada934ca5Virustotal results 7.25% Dridex
2021-01-25n/adll ca3589b42f6824dcb932812d91cf0e4e8e2186c85d60777e697d0f45e6d6da27n/aDridex