URLhaus Database

You are currently viewing the URLhaus database entry for http://ddl8.data.hu/get/394672/13257208/Bafwpd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2141026
URL: http://ddl8.data.hu/get/394672/13257208/Bafwpd.exe
URL Status:Offline
Host: ddl8.data.hu
Date added:2022-04-11 07:32:56 UTC
Last online:2022-04-11 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-04-11 07:33:13 UTC to abuse{at}telekom[dot]hu)
Takedown time:9 months, 15 days, 2 hours, 50 minutes Bad (down since 2023-01-21 10:23:55 UTC)
Tags:bitrat link exe opendir rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-30Bafwpd.exeexe 1163c08ef703102f0dbd56e629efbb4dbffca033d97690557880864e55efd5f8n/a 
2022-04-25Bafwpd.exeexe ca1c5656cf42853895526560f01436dd63e68eb5470de9f419c87a7b6824b2c1n/aBitRAT
2022-04-24Bafwpd.exeexe 5ba8220e0ed3a53d05848a8c91f3b5418e58804d0b5253b0f28895abadde011dn/a 
2022-04-24Bafwpd.exeexe 0949c80f5da9420bc73890efe276c679fd0fdfcfe2e8394caf380310c22353a2n/a 
2022-04-21Bafwpd.exeexe fb8062823a17341aeed35fa03a4d4f8d7a2351a7c87a33f8f4a61ef798f6b6f3n/a 
2022-04-17Bafwpd.exeexe cf746deaea3bbf947d1d0bc068f5d8f64c1bbdbc6b8f3a59a0453efbbd5caf54n/a
2022-04-11Bafwpd.exeexe c8906b045ca5733129e92f9e5b97e654ee0b321b1323b316866de4e8c976a601n/a
2022-04-11Bafwpd.exeexe 44e1fc8d3558bd5caa25ec85f99363873fefdab67ec1a478e67a93ffa993c850Virustotal results 28.99%BitRAT