URLhaus Database

You are currently viewing the URLhaus database entry for http://redwingdemo.dukaafrica.com/wp-content/Ad4DFk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307027
URL: http://redwingdemo.dukaafrica.com/wp-content/Ad4DFk/
URL Status:Offline
Host: redwingdemo.dukaafrica.com
Date added:2020-02-03 17:37:45 UTC
Last online:2020-03-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 17:38:07 UTC to abuse{at}ovh[dot]net)
Takedown time:1 month, 26 days, 0 hours, 27 minutes Bad (down since 2020-03-30 18:05:54 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-25aTHn6iDvS4C9NzVRZX7.exeexe e77fec5324124ecbeacc9dff612dc922166b7de228996a7f6b669559e1861c79Virustotal results 73.97%Heodo
2020-02-0567sJ4rOpjG3PO.exeexe bc3af4ac4fc3a4fd0cec3aa28d29c6a0106ca86aa57e145ad0ac92483c4bc948n/a Heodo
2020-02-05ng2Zrs31ym77m7R.exeexe db767dc3b3ebad70d0cdfcbffdb21caa04a5f11a552790071a4ffa72bde9cfbbVirustotal results 23.94% Heodo
2020-02-05vVglnTxNwDD8Baiw.exeexe 8a338aa5e4dbdc3707e393eea9afc480deeb12cfcbb35c256aaa7409d95e7836n/a Heodo
2020-02-04yFxeiBLuBL8nN5zOs.exeexe e0613d89854e76418b4b9e10e070f787b1455d35c692725474915959c72559c8Virustotal results 24.29% Heodo
2020-02-04XZUU79G47BUMyeeX8FhS.exeexe a08378cd4cbae971fd29b9a4cd6a730e450de722059fbf113ab866e5217929b4n/a Heodo
2020-02-04fmyyDG.exeexe 886c4a5e2c859b400271b30f87cbe22be9123648119f8e7ec4b62308cc0387b8Virustotal results 24.29% Heodo
2020-02-049v2n3dVI.exeexe b713e7059eecd886dece75ef046e9ac5be92ed8fa9f3ce3b6d7661bbe3fad6ecVirustotal results 20.83% Heodo
2020-02-04RGJjueT0B1p0V0gSV.exeexe 56f07e1ad8fd85fb4673a768c5bd109b43241428077a95cbffd8165e3a9364c6Virustotal results 18.31% Heodo
2020-02-04mF7J3cSTNVRWTnIsWWIs.exeexe 86989c9155e7c7f65d67dd0a5ff915b42cdbe6e602dded04194a8789f08262f9n/a Heodo
2020-02-04ncnZv04laLSNVSDugg.exeexe e9a899df39c55773d123ccf372ca886941b4c7da1e42e87baec266b24cdaa6abn/a Heodo
2020-02-04AZyyPmYLUu7ya6r.exeexe 0d987112081c2e2e8dd25a18b65c37546a9e42580f0f96ea3e181adcb1126fc8Virustotal results 19.72% Heodo
2020-02-04NknA.exeexe 93fc54f8af621ea9edc855dec2d25a519cf9f5f10d38f388665cefe9a5959405n/a Heodo
2020-02-04r6PotjC5.exeexe 227fa73ffa3e08a7f53f10f06e4bb18aa3b7aa6e9aa33ab949b91a9631d9dc86Virustotal results 16.90% Heodo
2020-02-03tpwBArgSNeEM.exeexe 08652f5ab0419a8cce61aa06b649256b7114d15fde9cbaad50077afdc86c23b2n/a Heodo
2020-02-03KK4.exeexe c1fa3b0e1a086ad5053bf376538379be7d2d7aff3ef3da22f0cdcb3c58df4be9n/a Heodo
2020-02-03KCLb.exeexe 06be4610a6b7fbc7659ea8c2904b1473a0d2925d225a67a8cc1f61ec8631ebd8n/a Heodo
2020-02-038xgfOst1kyH.exeexe 67ec9894143eb4bf3b9741183717cf372fdf2532ae906d14471e2e10d9c7cb0dn/a Heodo
2020-02-03erJx.exeexe 63c4162bc4c04d8b26744287280b0dea2c52b0649372aa509c2b77cde6aa69b4Virustotal results 12.68% Heodo
2020-02-03LgGDiiuEXxsU.exeexe 925b3d736f518e89a30e2b77b49daf9ecff02b1e5821efcab4c2995a60b4e96fVirustotal results 11.11% Heodo
2020-02-03sYwY709QM9hSvoC6Yomm.exeexe 197753da03ed1d957048fb3fa2c94b9fc5ccf0f24fbcce6279a67675fea7b4f1n/a Heodo