URLhaus Database

You are currently viewing the URLhaus database entry for http://dragonfang.com/nav/tepHch0F/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427176
URL: http://dragonfang.com/nav/tepHch0F/
URL Status:Offline
Host: dragonfang.com
Date added:2020-08-07 12:30:17 UTC
Last online:2020-08-07 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 12:32:08 UTC to abuse{at}a2hosting[dot]com)
Takedown time:5 hours, 23 minutes Good (down since 2020-08-07 17:55:39 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07DsN.exeexe 1b9a26aa999d1eec382674fda3a09e622fcb7ac507359ba481c52751a8bbb6c5n/a Heodo
2020-08-07Wgrjit9bqy4S.exeexe 9dc680ea88eaa271bd9acc35a3231a660625b03fc83145e6f8aee2955f6f6323n/a Heodo
2020-08-07hyj1.exeexe 3751aba064ec4a245c59f39147bf3a33bd519053f724079e347291b8ade52dc7n/a 
2020-08-07BaajCzRs.exeexe 4a6cd8e0584180fe21e13a965cc22bd3cdd2ff4eb8628f3ffb76ff294d1cb9f0n/a Heodo
2020-08-07YzOoygl0.exeexe 805910f525978d99dcc8d683f36c5f389626b7b85f546bd1574cf9a99c5e74a5n/a Heodo
2020-08-07zOmF7DmSXJ59EtI.exeexe 65ee7960df7ffe647c98040de9494274d3d2c757ee1fde7a2b168dc8c7600b12n/a 
2020-08-07kAAkMETLEGslwroiMSG.exeexe 48f9c21cbc5ff4f795d2f981ab058a208a5fc0eea430661d2f0dbd657067ceban/a Heodo
2020-08-07LE9bQ7t4QxpcFIlB.exeexe c61fd47e632cc0d0bbe23ade8445513b18eeb054ca48c9ba40bd909075c3ae7fn/a Heodo
2020-08-078NXq7uLqo9EIPP6.exeexe 62625f44d4cd0db1f0880304702a00396285a170a1af92cee4912784a2b39cadn/aHeodo