URLhaus Database

You are currently viewing the URLhaus database entry for http://dingesgang.com/wp-admin/rdZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178439
URL: http://dingesgang.com/wp-admin/rdZ/
URL Status:Offline
Host: dingesgang.com
Date added:2019-04-16 07:38:06 UTC
Last online:2019-04-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 07:40:06 UTC to postmaster{at}myhostcenter[dot]com)
Takedown time:1 day, 13 hours, 58 minutes Poor (down since 2019-04-17 21:38:49 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-16FOaAYEdnYp.exeexe 42d5b442bcba882b9b67d483d983812918c8f16bf244617e5125e54ed39c45b4Virustotal results 10.61% Heodo
2019-04-16ThLuC6D8.exeexe 04c2bba4e7b9c62d86d2b1cedf5b51020b3b3d110b0a5817347cbd5ff6c99d6en/a Heodo
2019-04-16jPqID1BF0VAE.exeexe 10544c3292c37c6162f605414eb6c2fcced36c1d6f7a53a939f667ea38009e7aVirustotal results 30.00% Heodo
2019-04-16ahxurQ5O.exeexe ba4923a2d5c690839cffc9455d029e1899a54fd63657c84de75b4209146192ecVirustotal results 27.27% Heodo
2019-04-16zEQZjfJjG9.exeexe a4df61083dd7b36ba7beaef43e3136350a0e2676f8566070062af9d5f9c7c3ecVirustotal results 28.79% Heodo
2019-04-16ttdKB9xyXN.exeexe 3cc6567dac689b169d5e856c668a29c758a4d384cf3392cbc36ccfae375de9c8Virustotal results 29.58% Heodo
2019-04-16F3I84hFq.exeexe 5dbb626a0c4ddb0fe2b8cdf0ac5f420a267b701a4a01306a80b99a2d87c067e3Virustotal results 28.36% Heodo
2019-04-16u0P1pu8HSlSW.exeexe 506d0e224b4ee201f06b90a465aa5dee50bed2db3d6f6724e7d9515abeda4faen/a Heodo
2019-04-165J5yv17l.exeexe 4ef40c6efbbef7b8bf448aa59f65377506a27c87562da8d6ec0e2ec2b654a0f2Virustotal results 30.43% Heodo
2019-04-162J8oJssoBS.exeexe 42a9f4399c862a9ad31399e7160c90b91d4507cc38da90a80b68f2ff0482e562Virustotal results 30.99% Heodo
2019-04-16hllBzm8R.exeexe ea23b5ed0da6ebb6dc90eb1fa2e5951edbf48555b5a7622ded42c5ee630c56a3Virustotal results 24.24% Heodo
2019-04-16L7pcKEsFg.exeexe 03f858d4cd9e50564db2b0441084f54514a7606e4ab57a34b2b6ab1edddafb2cVirustotal results 25.00% Heodo