URLhaus Database

You are currently viewing the URLhaus database entry for https://mail.rigid-group.com/jp/phpformbuilder/plugins/bootstrap-select/dist/0z42D3MM7x.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:990380
URL: https://mail.rigid-group.com/jp/phpformbuilder/plugins/bootstrap-select/dist/0z42D3MM7x.php
URL Status:Offline
Host: mail.rigid-group.com
Date added:2021-02-04 15:11:16 UTC
Last online:2021-02-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-02-04 15:12:18 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:3 hours, 55 minutes Good (down since 2021-02-04 19:07:33 UTC)
Tags:CoinMiner.XMRig Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-04n/adll 455e442d7efbb5712011f183c27f0dfa61297c938de00d9e649240d7bb83a56dn/a Dridex
2021-02-04n/adll d52402cca93f6bfb7b8ef2351a931a3ed0efcb9cb628119753cd283ca960fe9cn/a Dridex
2021-02-04n/adll 43985241fc96c46dcbbe28227711db6c94bd211d833658fde705b820198ad11dn/a Dridex
2021-02-04n/adll 56b8a3cdbfa6d2f79e7e8e2b0860d8f5fb14578e871eeaa3bcd0fbc89853ce4en/a Dridex
2021-02-04n/adll a28ecbd1cf35e41412a3464c7a04f985164bf052da0a3593f753df2a9f1d6f41n/a CoinMiner.XMRig
2021-02-04n/adll 695c8cf795799eedf8cf44f177708dfa50c412661fe6807fbd4a1a7f53dfcb1dn/a Dridex
2021-02-04n/adll b60d9bf847c8343438cda1b9bf66cc2ffe3c364086eca57c99a65e1354e8d812n/a Dridex
2021-02-04n/adll cafd19092a9264ea11a1aaaa9adfbd049205f62f2ba49c4a20a9935cf3f95802n/a Dridex
2021-02-04n/adll cd7111d5ba2b9ae14f13b32d76d0531055f5bd930df6e3fd6ec933d5de3eab01n/a Dridex
2021-02-04n/adll f5d28c8747f474f442f3bcd1bbc7c49e582f0775d8855739a0426bff18cccd4dn/a Dridex
2021-02-04n/adll f5c7895e561624fec517b6230d0817bdc62d5781cda22b10ca646e6407c0db49n/a Dridex