URLhaus Database

You are currently viewing the URLhaus database entry for http://waterdamagerestorationashburn.com/AUT/MDU.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:168878
URL: http://waterdamagerestorationashburn.com/AUT/MDU.exe
URL Status:Offline
Host: waterdamagerestorationashburn.com
Date added:2019-03-30 06:21:06 UTC
Last online:2019-04-29 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?):mail Yes (Ticket DCU001148542 created on 2019-03-30 06:22:04 UTC)
Takedown time:1 month, 0 days, 15 hours, 45 minutes Bad (down since 2019-04-29 22:07:29 UTC)
Tags:exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-29n/aexe f4a8d305e61b4e6025dbf6068b7e9cd97243d526c16d003157fd7a5acf2128d1n/a NanoCore
2019-04-26n/aexe 586ea715db5414de1711d12b211e91a561983e7af9ae14e0b8c56e251e70bd3en/a NanoCore
2019-04-25n/aexe e526539864ba0bae803577227486893d881e7ab0f56f83791fa5f9000b719352n/a NanoCore
2019-04-24n/aexe 55234d72d494e6fff1f0b40a1d005aba38a82aff4ba3052c1b1fb2490d981a2cn/a NanoCore
2019-04-23n/aexe 30171f124cb74d939a2812984c2096985e7f2ead97c61c292712de3984cf1141n/a NanoCore
2019-04-14n/aexe b6075f9eb2d73be9da560a2b77783f9523bbdb8594c60c331f71dcbfbccb7946n/a NanoCore
2019-04-12n/aexe 19626cd4ebe8d8073b101eb19e62b21d0d12182bd37dfbb7cef86b0fc458f00en/a NanoCore
2019-04-12n/aexe 874275fa813d1c9d7bc12d3f569f39d6aea9e0cec54c06bb3e580d5d2a397ce1Virustotal results 28.57% 
2019-04-10n/aexe 58fb9f1cb70700fcabbf77f48d6e4ae07347071b3f2e564714c2d8ba4342346bn/a 
2019-04-09n/aexe 35e1bdbe1882160e923c226f2720407ae406cc8ccef8599c07fa907a82c15f7an/a 
2019-04-09n/aexe 19665a17d9a5462739fa57137183a504d92a5539142032f4abee9663f79e60b6n/a 
2019-04-08n/aexe 6e527da2cb6e3c7b5fea7eb85117fecbc4d4a2ba3de943c47b7e8ad60738eda8n/a 
2019-04-06n/aexe 26f4e5c388cade7a9ec4e5700359dd087096a8c20e10e6326044e11c075fde25n/a 
2019-04-05n/aexe fadb31083aeb8150e8fb535d340971b72161bbfdceb73c9dee009e74c513b22cn/a 
2019-04-04n/aexe b2b1f6ad3fa2ee009ac6a193714b74fc7145d88b08d2bdfe3a9499d7a27b8c4cn/a NanoCore
2019-04-02n/aexe 4493b006d90e8414f932925d2c0d81745d3d884fa6388e2235b707239b18b79fn/a NanoCore
2019-04-01n/aexe 002fb9b9a8e72e1ef9cca5ee2a1ffe3624a11a61e249083728aea3d1eb2e03ean/a NanoCore
2019-04-01n/aexe a82c78edffc68d5928cd5034df46635dcec05d08775a62ce43a17b317ebf537en/a 
2019-03-30n/aexe eed1e211332bd34c17c47511f6bd6b1dd424f248df8fd926e1940b67b8a39765Virustotal results 36.76%NanoCore