URLhaus Database

You are currently viewing the URLhaus database entry for http://dragonfang.com/nav/1ogg550282/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:197725
URL: http://dragonfang.com/nav/1ogg550282/
URL Status:Offline
Host: dragonfang.com
Date added:2019-05-17 07:49:09 UTC
Last online:2019-06-18 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-17 07:50:11 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 month, 2 days, 8 hours, 19 minutes Bad (down since 2019-06-18 16:10:07 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-182ioj8.exeexe f1c04fe9bad284c27802f68bdbeae1f8fa8a964b25fb1daf251435273549210dVirustotal results 25.71% Heodo
2019-05-18w0eanpw7fxolk2.exeexe ea476bde26c2ee905eebec36b92c2413fd44bca34038c12c962816238ed3dfe1Virustotal results 26.76% Heodo
2019-05-1717zfwr3guu4j4.exeexe dcff10be51a9cefed367d2a5dd319e531d518c37ac7cdece97bb0cb44132178cVirustotal results 29.58% Heodo
2019-05-17pzwvx.exeexe 89007bc0d5b127eacd69f2b7b2308060a2d3d9f0a0fcafb43f039996f6e953fdVirustotal results 35.71% Heodo
2019-05-17bzrdz1vgwgt.exeexe 9e2afcf53b382a27c6c4b477ca5f2de1eb2e0dc25bec9eeae30ce64166d0c616Virustotal results 35.21% Heodo
2019-05-17lpnyz.exeexe 2329223b71b5afc522f3db436f3f494b00feef6390fa632738a068b35ea1b2dfVirustotal results 26.47% Heodo
2019-05-17rh1eq832zm.exeexe d977f8609ea47b593773b374db94ce929479d71da28e5a602e155557460378dbn/a Heodo
2019-05-17pg988fsuk.exeexe 29c33c50123e01a4b87f834ec7c106e8c0745aac0bfacb5694401c8239ab44c0Virustotal results 23.94% Heodo
2019-05-17mkulyx.exeexe aa0a18052aa46a75d0fb371673fd91d6caf7a11f49916b2f2223ac779795cf09Virustotal results 23.29% Heodo
2019-05-17wyoi4o4m82sucpp.exeexe 753590e3ffcc3be801541f9eef7386078037a3abb310e7189a61ad5ee5ecc716Virustotal results 36.62% Heodo
2019-05-17m607fm1d3x42r.exeexe b3c9f36107f11c0277a984cabdfee49af052ba176df5153999ad1978bf58c642Virustotal results 35.21% Heodo
2019-05-17azjsuy99.exeexe 19a4827d85259f0525409fefb00499f1786bc807020c707575b3f5c22ab5bc64Virustotal results 34.72% Heodo
2019-05-17u6mz3mwalvc8q.exeexe 9f163bfe37d14f227683e7878c90f4220e0c358a50d8c363ce73fdcb6022b8a0Virustotal results 35.71% Heodo
2019-05-17y8k3bjyz4vz.exeexe 0cf0847f8d329041aa8f30a35f62067077d7c7127366d76002cfde89285c801bVirustotal results 32.88% Heodo
2019-05-17ipai7axqdiy.exeexe 273b13b692817e33ad527583c8594e133d378bfc4fdbd09be1c9228253024192n/a Heodo
2019-05-17ccg8e0.exeexe 5a3a34b4ce6e7f0c123fb0890ff54adf2130f5eda950b909cbf0b33dbf05a8dcVirustotal results 29.58% Heodo
2019-05-17ywg3d.exeexe e5cc52432abb7c0bea276194dff998e40d18c6e2e097bd75ecffb3e3368fce87Virustotal results 29.58% Heodo