URLhaus Database

You are currently viewing the URLhaus database entry for http://tunedinblog.com/wp-includes/prosperz.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:978553
URL: http://tunedinblog.com/wp-includes/prosperz.scr
URL Status:Offline
Host: tunedinblog.com
Date added:2021-01-26 06:49:04 UTC
Last online:2021-02-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-26 06:50:04 UTC to nic-ipinfo{at}gmo[dot]jp)
Takedown time:29 days, 6 hours, 44 minutes Bad (down since 2021-02-24 13:34:12 UTC)
Tags:exe opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-01n/aexe cb02d2d2301b7b9fb6a36b47f26a0bf46c9a3312cf15593322c93f41ac802ba1n/aRemcosRAT
2021-01-29n/aexe faca912519753db658f9fe65aa76de01a6e2588be287e82b4dea48de84fc765fn/a 
2021-01-27n/aexe 377ca72fec29dacf88f92fda96c917a614bdd5aa9c120230afc4c262931de79an/aRemcosRAT
2021-01-27n/aexe 0f03217f712d3a86e138d708cb12fca4a2fc65877b116bf1aeb853d32d379051n/aRemcosRAT
2021-01-26n/aexe 013078abe0a58bcf4c00e1c213c54478b30c1c25001d2c963f451bb5aa6324a0n/a