URLhaus Database

You are currently viewing the URLhaus database entry for http://demonware.online/AuDemon1/dashboard/programs/uploads/OYjNZ83sjKRthbBx6R8PTMnhwyUfbG/dwrblood.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2197408
URL: http://demonware.online/AuDemon1/dashboard/programs/uploads/OYjNZ83sjKRthbBx6R8PTMnhwyUfbG/dwrblood.exe
URL Status:Offline
Host: demonware.online
Date added:2022-05-16 12:43:06 UTC
Last online:2023-08-02 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-07-28 13:03:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 year, 7 month, 6 days, 1 hours, 45 minutes Bad (down since 2023-12-13 14:29:40 UTC)
Tags:32 exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-01n/aexe 3d275fea302f5bab0d04f70d85de674f6abb72fab1d7db87c218cf5976da1ac6n/a 
2023-03-06n/aexe 3d7699832c4dc30a4a73308ac294f3be2d23778864b3757b6a58a38e10f5326fn/a 
2023-01-11n/aexe ca9ea2e7431d0da5d8f8e3b4054184c7135805cd2776842444dc4a60f0f6913dn/a 
2022-08-17n/aexe d26e1cb039d09ed9adf136a5f290b01d3fa0b35ddb95ac2fa04dd15ed145c439n/a 
2022-08-10n/aexe 56f8ae98568bbfe3291bfdad9797b5ab88ca40eb91a8eaa3f969de360dc94797n/a 
2022-05-16n/aexe 34780db137a84afc3d8957def954127c724fba4187055e49b875481203b68163Virustotal results 45.59%