URLhaus Database

You are currently viewing the URLhaus database entry for http://garenanow.myvnc.com/CIG.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:128673
URL: http://garenanow.myvnc.com/CIG.dat
URL Status:Offline
Host: garenanow.myvnc.com
Date added:2019-02-17 00:24:18 UTC
Last online:2021-04-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-02-17 00:26:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 years, 2 months, 20 days, 17 hours, 42 minutes Bad (down since 2021-04-27 18:08:50 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-06n/aexe 311dca44685527515bfc01d6c9a1e6b46b57c41fee56f1ddd5cea11328ff1e82Virustotal results 16.92% 
2020-04-08n/aexe 13870ef190925063bf7c11309b51f17b47f7f1d4e1c2e0cb3a9bd7ff977ad7eaVirustotal results 17.91% 
2020-02-08n/aexe a55455263214345e81ce83582fe67035bceda9e7214e626854ff858f674d225cn/a 
2020-01-09n/aexe acdeb369cdc33dfaa2a63cd228fef32cefdae7d1efb4dfc989671f50d2bb314bVirustotal results 16.90% 
2019-12-20n/aexe 716216084a19a0d174226c58fd48a01047207952f1d04f4328d1a74e9abac693Virustotal results 16.67% Heodo
2019-11-28n/aexe 08e9bf83fd8489ebd9a42e19ce7244592a2a1016e80c0b5d3cc7f2306ee3350eVirustotal results 17.14% 
2019-11-23n/aexe 06ac6c6a6d1dc179e2b1d93579efa08ea3a3261b7ab81b89d6bae2563d4138d5Virustotal results 20.55% 
2019-11-20n/aexe f8aa32d88540d486d711dc042ec51d4a90cf335c300109c36eaffb1f76c15f20Virustotal results 14.71% 
2019-11-20n/aexe 17d6313391df9d715571966edc3d334486e58e90fcbebc9648db96c82182469en/a 
2019-11-09n/aexe 4353714819561d4e7797c914ff5210a4c1023a7d7d7e7e10f3e48eaf5b08c1a6n/a 
2019-10-14n/aexe a11aa5498bb03a81baa30459681936aaf1afeefcc39e063bb9ff8bddeec63b9an/a 
2019-10-08n/aexe d3b860c799d8ddd20c6c066165129902bff32be038224a76a16245a666bc9973Virustotal results 21.43% 
2019-08-26n/aexe f7c8c473e511a4838660a2b2475947c576192c4b93d1b4ee3baf2ea5b2bc20e0n/a 
2019-08-18n/aexe 8eaf1f96baf19da449f3a2dbee50830baad97ebf36d654ae5d81090a5e1d9229Virustotal results 14.49% 
2019-04-19n/aexe a94913ac9e1eec4f91e621233a848428860ec4a82da65b4d80f79914826a0c86n/a 
2019-02-24n/aexe 29e0374a105fea9130acb3690ca69fc53e1c16cabae72013f84ba9781be9f27en/a
2019-02-24n/aexe f04fc2438ebb599145169cf9efecf9e70820681a9cb6dd592a109dbc5f0591a4n/a 
2019-02-23n/aexe d9d19e25e6b4dca70569cc76ab369ebbb036d5e631b9c366ae27e356c43594f4n/a 
2019-02-17n/aexe b870157d5c7f707932cdd55ec273e5d14dd6e309cb3c1cf1971f2928fc960492Virustotal results 42.25%