URLhaus Database

You are currently viewing the URLhaus database entry for http://dragonfang.com/nav/dwfeO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178681
URL: http://dragonfang.com/nav/dwfeO/
URL Status:Offline
Host: dragonfang.com
Date added:2019-04-16 13:08:15 UTC
Last online:2019-05-15 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 13:10:08 UTC to abuse{at}a2hosting[dot]com)
Takedown time:28 days, 16 hours, 13 minutes Bad (down since 2019-05-15 05:23:13 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-18OxyH0QYhwQXj.exeexe 1b6aa692ba88e13ddec659e9c601d305146fba99e16181467cdfe49c7b109918Virustotal results 18.18% Heodo
2019-04-18miS8KwaXvFab.exeexe c693966ced492821a1c9eb83b7ae288b75690b9c15731fda514f8677bf846722n/a 
2019-04-176gnmAzKd0H.exeexe 8563ecda0a46762d82674a0381e1bc99b8518cbb54691ad0b294c44a5e2074a0n/a Heodo
2019-04-178ELMBsyz.exeexe fe7f3c4e834e67b455d62b5ddfdfbe27acf699641e163038e4e320c310f44ae0Virustotal results 30.43% Heodo
2019-04-17FcEjEVQE2SoF.exeexe ac9915fc4b0a1fdc1a853e119d0508e290952d43ee16e0abae3cff26c2ed6471Virustotal results 28.36% Heodo
2019-04-17ysfyMw4DZw.exeexe 9612e7fa0091067ca86a9797e4b2995bcd736ffbe98242f69e02081252d185b1n/a Heodo
2019-04-17Ufn0u0hw.exeexe 50843f1c34dbe3de77a86615f7cc0064ebdabca83d2248dae7b93fbf8c7bb80eVirustotal results 39.73% Heodo
2019-04-17W3nHj594.exeexe cabd6a707a679f24d05dc9017033592b7edefb0d4ff28ab374db176c5488ca42Virustotal results 10.61% Heodo
2019-04-17cbe1RK1spK.exeexe f349869e1e5d51c932e1645562ba7bfe325faea0f049e81703325207c71103beVirustotal results 37.14% Heodo
2019-04-17iBMR4iiU.exeexe b1ff5735dbe2912987c40cd61f8b68ea0f3eeff34d4bd724586b623d7f43f18fn/a Heodo
2019-04-17cigyseZjW.exeexe 9c7dc9f71163b551d93c0111ff12d5bb9a65d901b8149f09035e52df6dbf1834n/a Heodo
2019-04-17MyQ8mL1t0.exeexe 3286340a92b48cf2a64c066f4cec1b078d9c23df987dd9aa07f249fffc5a9cbfVirustotal results 35.21% Heodo
2019-04-17mJgbuRZY.exeexe 4201ca0efc7ee82ce843903a5ecd7f96bbae37b56ab00405817a96b241d06debVirustotal results 35.21% Heodo
2019-04-17OzGQqFuTKN.exeexe 1ec9145cc88f7e619398955d6377ea4a6aa2f5fc8d53b87a467468d284352d61n/a Heodo
2019-04-17T0AJkfINru.exeexe 22d4075bf5828ede0c20dbea9023775ebbffb6e867272945a6a69697ea015c8cn/a Heodo
2019-04-17SQpXx6vPF9.exeexe b73cf17e6b1e9c8af706ff0cde0ac5956c991aee5c5eed838e339ca152fc2692n/a Heodo
2019-04-17prEkR5FT.exeexe 0911c843ef0b50a6b7359384d774350c43ea81970e47b6390782a3b59619df23Virustotal results 32.35% Heodo
2019-04-17nHEhFYKV3xC.exeexe 25806bac5ca5b7b3dc6f1cdcbc4d72ade84828ae4173a858c3e9fe028d51b7e9Virustotal results 30.88% Heodo
2019-04-16MMEFeHV111.exeexe 42d5b442bcba882b9b67d483d983812918c8f16bf244617e5125e54ed39c45b4Virustotal results 10.61% Heodo
2019-04-16Wdx2ZV3S.exeexe 40f5adf7de8605391f566b0f5dd159b2f78abf04741f0914346ba29d31c7b371n/a Heodo
2019-04-16up9017xH.exeexe 3d5d6478be30722d9bd8db096e17faa2d028a430bd584ac5204041d69106d33en/a Heodo
2019-04-16EcEY8WrhHQs.exeexe c3da3d50a58b61da152ef9324924304bba6ab3b0485140120dd2ae9f6e9a11c1n/a Heodo
2019-04-16PBmCXcxh.exeexe c481b71e426986b974b3b8a3438ed20e02acceb15e3cef087df32ee7663f34f5n/a Heodo
2019-04-16gtw7BDPr7V5.exeexe 4bba21068231dfd43232ff7dc61e0a7fb17195c86b4acebcf0bc395e24fe9a94n/a Heodo