URLhaus Database

You are currently viewing the URLhaus database entry for https://dapurgarment.com/wp-includes/ufd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:252406
URL: https://dapurgarment.com/wp-includes/ufd/
URL Status:Offline
Host: dapurgarment.com
Date added:2019-11-07 18:55:19 UTC
Last online:2019-11-08 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-07 18:56:05 UTC to abuse{at}exabytes[dot]co[dot]id)
Takedown time:23 hours, 31 minutes Good (down since 2019-11-08 18:27:31 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-083ewTLA84C2.exeexe c9d1f345957434b6925644a6e82c3a61f0620e785f2e0f5dbc6f0099cafa947bn/a Heodo
2019-11-08GWNTfxvZjufRCF.exeexe c64ca381d3329fbaea7e63fa5dd2a07c60ca3e267c882121e34837074fd81ac9n/aEmotet
2019-11-08B9f88bq66sQ1Wv.exeexe 84d4f539b32903bb1126b6bc32c9d4e90665d9137baac54172fadb7e770bae91n/a Heodo
2019-11-08DPMhxvJOeJaAMrEPd.exeexe c245ebf895eaaf4db04ab0d4439efd3655f906132125c002658fec3768419b54n/a Heodo
2019-11-08JE.exeexe 9451735c12cba9d2dcf274eb7a72fbebe98b2d4a29120820b88d13d14dbee379n/a Heodo
2019-11-08t0KcQLwMB08ftmxpcdfR.exeexe 53ff0c47776b3b6d7867458f0d9ebe85dd776a8d08b702404adfcbb4fa919ecdn/a Heodo
2019-11-08rW8klgFX.exeexe 09f4a501fd5f2b035eaa44e2c57711df8a14a0cbee6a3643121c293948d519fcn/a Heodo
2019-11-08jJupnBN5.exeexe 6e5b9bfb75c5d630bfa00b7ce633e1a216dc281089025577109dbdcb9f269dben/a Heodo
2019-11-08LdsvI663RnBHbxK.exeexe 1eb95e1f291f5742bebad2bd942dace5e6082ce67eb7e93e38d9edad646bd713Virustotal results 22.54% Heodo
2019-11-08fxcXtUR1AvC.exeexe 568ff9b41c9a1b474a379180abbc79800289d662eb1b98e52541792e60670a13n/a Heodo
2019-11-08wxXgHFgC2G.exeexe 335411cf68be7c5d11b53aa087958714e3428efd229f44e7c8eb09390aa20908n/a Heodo
2019-11-08s0AkDJlzft20JXg7SLz.exeexe 2b579d694803b8dc9a625f60e0d141dfa9e823851e230f35ed731da0330c9f29Virustotal results 19.72% Heodo
2019-11-08uEVhxdrMYFATh.exeexe 9e6a52ecbf3e9be86ba37d5c6c405d2ede9fc92ce1de806dd851a7dabfbcd43en/a Heodo
2019-11-08pvqGWoA8aFPj.exeexe f33f76752f7e7658a1467c6d5dea5f54adb86e0011a5a85f159fdc10e50880aan/a 
2019-11-08WCchHEXdP5YzHG9n.exeexe 79a52e399adeef9b4fd677632a59b6afbcf11ff17168965dc3caa72ff47071daVirustotal results 18.06% Heodo
2019-11-08eIWQy8.exeexe 84503cfc3cb485c9c03e2fbf67b3c9e91ace8b386c920b84cc0c0cd9c569678bVirustotal results 18.57% Heodo
2019-11-08prG0PwxNaTXrwzWlgsq.exeexe ff5aff38db33dc69e59bc65dfe07be7727873532c04d44eb51feb289334d582en/a Heodo
2019-11-089NaOh12sAhx09EVNwE2m.exeexe f843697d2ad0326b54ea847f069e167e4ccd7c8bd990c988bfd3317f4979e20cn/a Heodo
2019-11-08ZQEsC4vOP2aCJ6S5Dbx.exeexe 3a6ad88b235204bf37d3c3f939b32ed89e07b63b6511e1221ff3b2de1ef9379dn/a Heodo
2019-11-072P3V1zTf.exeexe 964747fae80b1124c96db5233c167ca4b035f8ff7272ffb3e3142fa798004a56Virustotal results 16.90% Heodo
2019-11-076up3OmZ.exeexe 7502df4231dec2f0a113325d6c28c376459d33a4acf6dccada5634a45a3df508Virustotal results 21.13% Heodo
2019-11-07fWwg1OqUeqXs2Rpar.exeexe fa3b17006ed40899fedcf3bbd67be0a3c0181c593527825c720b3653ff7d9cb1n/a 
2019-11-07N8uby.exeexe a3c69382286d6c0b0e33283781eed62faafd27b73e66cd9117cec09333e04a64n/a 
2019-11-074zYyodqg5KjM5YkkJF7V.exeexe 01300c48a3cd34acd4c063bc1011f3102a5608b09308aeac02e51b80e5d76a2bVirustotal results 19.44% 
2019-11-07zGyJ4E.exeexe d32a7bfebebc4ad64a7bd96ebf0a02097d2e38c156468d2693ed5b70a9425736n/a Heodo