URLhaus Database

You are currently viewing the URLhaus database entry for http://www.yds-en.com/update.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:9874
URL: http://www.yds-en.com/update.php
URL Status:Offline
Host: www.yds-en.com
Date added:2018-05-14 15:52:54 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?):No
Tags:AgentTesla link GandCrab link Ransomware Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-171.pdfexe 0960446627af5c6c05d66432efe515cc7b485e8896ae11933ba357f148fb314an/a Ransomware.GandCrab
2018-06-171.pdfexe 0e1ff91f3f95df5e13fc929fe8406bd080e99d0e60816a92cb2ece1507e34f99Virustotal results 45.59% Ransomware.GandCrab
2018-06-121.pdfexe 631ba5cc0d8eb1ad7e31b2688b390be6a4d871501d9bc0a4a37c4e2bf9c615c1n/a Ransomware.GandCrab
2018-06-121.pdfexe d46c7bc70ee391640720bfc4461dccb4d057f30a9c1a14133b5dac1f781d40cdn/a Ransomware.GandCrab
2018-06-121.pdfexe 23ba8f2046a65df0c728e32975d8ca0fdb30d979d67a0ada609534761cd73dd2n/a 
2018-06-111.pdfexe b9a5f6188b2113bf79190442700d6f20630756e1d82a541739edb012167301a7n/a 
2018-06-111.pdfexe ef9c5e300591d7f96c2c6e4c339a20e443f63c53d6bd2c75b1e67e560b257138Virustotal results 39.71% AgentTesla
2018-06-101.pdfexe ebba3191a9f0ae2c8173d43cdbc07b9eab8f82cf345cafd294c6c27310caad5fn/a 
2018-06-091.pdfexe 03f242f7f52438ed06b804665b2a6712ef8283b23027ce5fee6b422ad5dbb0d2Virustotal results 44.12% 
2018-06-081.pdfexe ef2cc603adea56cea76d70761ce4d61efe5c2d8e4a7f8d9d126a0d43928b5e80Virustotal results 36.76% Ransomware.GandCrab
2018-06-071.pdfexe db7d32c4df0f2ef0f76a110cf41834fd0c029f431821d59e27154c0410e9a0a7n/a Ransomware.GandCrab
2018-06-071.pdfexe cf109f276dfba6b25fb3d6e7eb330fe175337c0c6e76d05e2b3d5687d327cc98Virustotal results 35.29% 
2018-06-061.pdfexe 288187098761c7568622b70c559c64445d39f2b319740eb68272a16501282576Virustotal results 38.24% 
2018-06-061.pdfexe 8e7081b5af93457656ce514c848ceac95da7afd2d29390462112389b0cf82b68n/a Ransomware.GandCrab
2018-06-061.pdfexe 597c8c634ea78cc852a04062815cbf1ea64419956d7e845dddb0e9ce170397afn/a Ransomware.GandCrab
2018-06-061.pdfexe 6fa5ecdc0f56cee09281e94868a4d71220d1b1f384579645d3b7a1e4cbf8da0cVirustotal results 37.68% Ransomware.GandCrab
2018-05-291.pdfexe d02e755d1f132f06d12370725a7c639082fbf93f5c3965398ce1e2542c68491dn/a Ransomware.GandCrab
2018-05-17n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-05-161.pdfexe d2f851fd60e85be31a5c5015c1cab7021941a09dd274682124d85abaff49f641Virustotal results 34.38% Ransomware.GandCrab
2018-05-151.pdfexe 274776b15313ea525a39920b4900392f9ea6086c62fb7b2add0f607c8eb3ef38Virustotal results 27.27% Ransomware.GandCrab
2018-05-141.pdfexe 43a4b51f23ac8c863bbc1b22b58c743e7646b85def629ef1e92f81c36cadee54Virustotal results 30.30% Ransomware.GandCrab