URLhaus Database

You are currently viewing the URLhaus database entry for http://syonenjump-fun.com/pl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44253
URL: http://syonenjump-fun.com/pl/
URL Status:Offline
Host: syonenjump-fun.com
Date added:2018-08-19 06:22:08 UTC
Last online:2018-09-13 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-07 11:25:20 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:5 days, 17 hours, 35 minutes Bad (down since 2018-09-13 05:00:25 UTC)
Tags:exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-19284589.exeexe a9104125f80ddfe0cd34718361a3b01ed97630425adce350b84f123b3efe79bdVirustotal results 11.76% Heodo
2018-08-1970827916.exeexe 00caa539aa187eb971e78df22170d2946b9d5f476786063fd3bfc502463396f5Virustotal results 14.93% Heodo
2018-08-190612888.exeexe 1c31786bdb8a74fd53eb85a616cac298aa3799ef8833afa069f9a948832a21b5Virustotal results 29.41% Heodo