URLhaus Database

You are currently viewing the URLhaus database entry for http://www.wzgysg.com/update.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:9884
URL: http://www.wzgysg.com/update.php
URL Status:Offline
Host: www.wzgysg.com
Date added:2018-05-14 15:55:14 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2018-06-12 06:55:33 UTC to westabuse{at}gmail[dot]com)
Tags:AgentTesla link GandCrab link heodo link Loki link Ransomware Ransomware.GandCrab link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-171.pdfexe 0960446627af5c6c05d66432efe515cc7b485e8896ae11933ba357f148fb314an/a Ransomware.GandCrab
2018-06-171.pdfexe 0e1ff91f3f95df5e13fc929fe8406bd080e99d0e60816a92cb2ece1507e34f99Virustotal results 45.59% Ransomware.GandCrab
2018-06-171.pdfexe 5914fabe35cef45c9cc91aed175c3ee79f12c8a453943123ad8230b789b849ben/a Ransomware.GandCrab
2018-06-161.pdfexe 8909033a54dad3a734d9dcd3a199d75632b2a66d44b63a0e2785f4a1d79aa989n/a Ransomware.GandCrab
2018-06-161.pdfexe ad9b01e33049ce895a385f2c5f588a08e8cf88fbeeb8623448c0c37929fb5608n/a Ransomware.GandCrab
2018-06-161.pdfexe 689f028fe2b79a0fa06a9cebf76c3fc0fb715692e9468c15dc12785cdd771c85Virustotal results 44.12% Ransomware.GandCrab
2018-06-151.pdfexe 47bbc185f38feb5d7964a1f6fba8b6ccdf5d1a1c009178af4abdbcea90592e3en/a Ransomware.GandCrab
2018-06-151.pdfexe 8674ebd775a0ed6def752db25ee467e58b7505d0827ebe4e8d4e3b3970bae98dn/a Ransomware.GandCrab
2018-06-151.pdfexe 7e1a56698fc2de587002a6b33fb974ce8a976091fb2f645c26cb9c309e77b620Virustotal results 42.65% Ransomware.GandCrab
2018-06-141.pdfexe 939d3749a9bec418984bd4dd5e32abd270724d724565fca78396b7551c9fb043n/a Heodo
2018-06-141.pdfexe a69d0a93747e86d93e1531ab649ea9623b4985eb063290fce7e999d10241ffddVirustotal results 38.81% Ransomware.GandCrab
2018-06-131.pdfexe 88a6597fae59a940c0a0d54a914ef1e47ff13b3dec796920053ba2a9bd3719cfVirustotal results 50.75% Ransomware.GandCrab
2018-06-121.pdfexe 41b5e623939fabff5a9022fa72f6ab93a3b35c38be67506afea7a236593a16c2Virustotal results 35.94% Ransomware.GandCrab
2018-06-121.pdfexe fb96ee08822e6f7f3e1c607217c8cd471fb06fdd7d523baeb3a946b0fef5e971n/a Loki
2018-06-121.pdfexe 631ba5cc0d8eb1ad7e31b2688b390be6a4d871501d9bc0a4a37c4e2bf9c615c1n/a Ransomware.GandCrab
2018-06-121.pdfexe 23ba8f2046a65df0c728e32975d8ca0fdb30d979d67a0ada609534761cd73dd2n/a 
2018-06-121.pdfexe d46c7bc70ee391640720bfc4461dccb4d057f30a9c1a14133b5dac1f781d40cdn/a Ransomware.GandCrab
2018-06-121.pdfexe aaf3c5dd4fcc168954f6feeb407e6997abb2df8ca1f6f268261bb3ad726e5ae5Virustotal results 38.24% Ransomware.GandCrab
2018-06-111.pdfexe ef9c5e300591d7f96c2c6e4c339a20e443f63c53d6bd2c75b1e67e560b257138Virustotal results 39.71% AgentTesla
2018-06-111.pdfexe ef72768cfacf5d411812becfccde90ed63ecd98f3602d52eab419d1668cc948fVirustotal results 39.71% Ransomware.GandCrab
2018-06-101.pdfexe 920b927d0957d713b2f31ada8880f09948d52334e51fb68e0c209bcd08bc035fn/a Ransomware.GandCrab
2018-06-101.pdfexe ebba3191a9f0ae2c8173d43cdbc07b9eab8f82cf345cafd294c6c27310caad5fn/a 
2018-06-091.pdfexe 09cc3a51814031a99366a5c8fd2a5f1d91c35d91557fef5b334a6e31a7e112aaVirustotal results 50.00% Ransomware.GandCrab
2018-06-091.pdfexe 03f242f7f52438ed06b804665b2a6712ef8283b23027ce5fee6b422ad5dbb0d2Virustotal results 44.12% 
2018-06-071.pdfexe 612cfe2a22c31b2f2f6bbcff82e25038a632bac4a3785bcaaf4d8f86910cc457Virustotal results 38.24% Ransomware.GandCrab
2018-06-061.pdfexe 288187098761c7568622b70c559c64445d39f2b319740eb68272a16501282576Virustotal results 38.24% 
2018-06-061.pdfexe 8e7081b5af93457656ce514c848ceac95da7afd2d29390462112389b0cf82b68n/a Ransomware.GandCrab
2018-06-061.pdfexe 597c8c634ea78cc852a04062815cbf1ea64419956d7e845dddb0e9ce170397afn/a Ransomware.GandCrab
2018-06-061.pdfexe 6fa5ecdc0f56cee09281e94868a4d71220d1b1f384579645d3b7a1e4cbf8da0cVirustotal results 37.68% Ransomware.GandCrab
2018-06-051.pdfexe b99e8bee4b862797dad24e952f385f7c69d89a1223cae6a0f1a0ae3ffd698260Virustotal results 37.88% 
2018-06-051.pdfexe 8a7561b44189f55f34c0246df52df63d00285556cde72984e359917031e6ebacVirustotal results 36.36% Ransomware.GandCrab
2018-06-051.pdfexe dcca510f52b98b86980c07eeea06a4312714a7adfc62c6a4c66f5bd43c6132d3n/a Ransomware.GandCrab
2018-06-051.pdfexe b6a991d66125413e10b1f5ed0ac2559deaafb52248c3c28e4af5d10f9fbd0735Virustotal results 37.88% Ransomware.GandCrab
2018-06-031.pdfexe 91a9f37e7d10d6da919ee61e568644acb6f54f4bf962311fdb0cd9f361c4f91fn/a Ransomware.GandCrab
2018-06-031.pdfexe b152551a38dfbe3be877c9ace8305dc9e66055de1c0c08c88294c6a7830a7122n/a Ransomware.GandCrab
2018-05-17n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-05-171.pdfexe 70b2ad601664d79c07d96071f16e07aa637b380554fe5ff131e0b739bc68f82fVirustotal results 37.88% Ransomware.GandCrab
2018-05-161.pdfexe d2f851fd60e85be31a5c5015c1cab7021941a09dd274682124d85abaff49f641Virustotal results 34.38% Ransomware.GandCrab
2018-05-161.pdfexe e804fe8fe0573df48218d70c19e21145d504da5ed3e3e6100442e3b52996c3b5Virustotal results 37.31% Ransomware.GandCrab
2018-05-161.pdfexe 4dfe18b3f86e0435ac138845e74b63243d58ff9dc4210cc1d80e9508318fc6ccVirustotal results 46.77% Ransomware.GandCrab
2018-05-161.pdfexe fe26b3e32dd87960bb9b6081e49f618fe85b0a9593cc755a086284f2156d5b3bVirustotal results 43.08% Ransomware.GandCrab
2018-05-151.pdfexe 79ea45b1141089ca6ea7b8dc59cf7f44912982c7e0f890c15a577528f9d657dbVirustotal results 30.30% Ransomware.GandCrab
2018-05-151.pdfexe 274776b15313ea525a39920b4900392f9ea6086c62fb7b2add0f607c8eb3ef38Virustotal results 27.27% Ransomware.GandCrab
2018-05-141.pdfexe 43a4b51f23ac8c863bbc1b22b58c743e7646b85def629ef1e92f81c36cadee54Virustotal results 30.30% Ransomware.GandCrab