URLhaus Database

You are currently viewing the URLhaus database entry for http://dragonsknot.com/cgi-bin/privata-ef6vmr6p4dckh5v-rsg1x9pia7e/custodito-profilo/EG0Uu6-MI8vgLmG1fhb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272614
URL: http://dragonsknot.com/cgi-bin/privata-ef6vmr6p4dckh5v-rsg1x9pia7e/custodito-profilo/EG0Uu6-MI8vgLmG1fhb/
URL Status:Offline
Host: dragonsknot.com
Date added:2019-12-19 07:30:05 UTC
Last online:2019-12-31 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 07:32:03 UTC to abuse{at}silverstartelecom[dot]com)
Takedown time:12 days, 3 hours, 8 minutes Bad (down since 2019-12-31 10:40:32 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19fatture-836445515201.docdoc b6c23e16e5f78e9b6c56583020bbe680d7f45ef429bd6c0fb39047b9adf3d31dVirustotal results 23.33% Heodo
2019-12-199331276.docdoc 5753137592ac6f6c8fa9e24ae41031e5b0a62f073f440d65ffc93d2107adcc2dVirustotal results 22.95% 
2019-12-19fatture qqo742m13q22m.docdoc b51ec74516a3c5ae78be8e68183c383e417de389b933f34975ada84b0f087d60Virustotal results 20.97% Heodo
2019-12-19FATTURE PN05210929042.docdoc 78817494aac2439537a26b88b92a769bdcabca8e004e90c29a6f9a7d76dbc34aVirustotal results 22.03% Heodo