URLhaus Database

You are currently viewing the URLhaus database entry for http://pandemic-info.com/bin/mapdata.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:983727
URL: http://pandemic-info.com/bin/mapdata.exe
URL Status:Offline
Host: pandemic-info.com
Date added:2021-01-30 01:46:06 UTC
Last online:2021-02-05 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-30 01:48:02 UTC to abuse{at}alexhost[dot]com)
Takedown time:6 days, 19 hours, 34 minutes Bad (down since 2021-02-05 21:22:45 UTC)
Tags:Amadey ArkeiStealer link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-05n/aexe f00a042bb3aa0fd344f98c2f2f868a70ae5ceeaaead2c66302b9a53199e8f991n/aArkeiStealer
2021-02-05n/aexe b2ca76052b184c69881e79f3f7549ae884f38a57f50f5801fa40aa953f20b11bn/aArkeiStealer
2021-02-04n/aexe db0561d243c64facc962cb65a8832c25dd1c95be774a3690e2c91502e92a6b06n/aArkeiStealer
2021-02-04n/aexe 19a595917039b249ebebe0e98a532a61585b0a4189bdb44a28c73523feed14dan/a
2021-02-04n/aexe c10df7ff1234d45342b534153be81de8f252e88ae00413bdd476ddfc05d542e9n/aAmadey
2021-02-03n/aexe 320a5f1b26e4b73c4bde7e447f2505459b6e9c2b70c432a68bbabd84b46ca988n/aAmadey
2021-02-03n/aexe 53237c2782ec5dbdabb8350a3ef5e8c25662436052e92ae1300f3f41be984ea6n/aAmadey
2021-02-02n/aexe 69248232555fb6f59a356e23da4dd883def9d70a0da48ff491b951c008afe626n/aAmadey
2021-02-02n/aexe 031870de77730956ddb3d44812996171077d01364a1dc9ffbf27ab52918de6c6n/aAmadey
2021-02-02n/aexe fec65142a9b98d138fa49f1f94cc4e25999220745b97b10c4531a3bdcf4bbef8n/aArkeiStealer
2021-02-02n/aexe fc96c80feb56e4d65f40682bb63a88e52682d05b760e13b1df8a7d454d16538cn/aArkeiStealer
2021-02-01n/aexe bed2f26c88cb673e07a6c880dd946151584a215f3da9980d6b14fba2d01ec6f3n/aArkeiStealer
2021-01-30n/aexe 176bd9797524c68e89e2ce41b1c4975d5affd1aa6a193d71819b422f919fdf43n/a 
2021-01-30n/aexe 6e9a7610a7e46968d211763942cc8508e1c07cfbbde75f8a9ae70926eaf991efVirustotal results 34.29%Formbook