URLhaus Database

You are currently viewing the URLhaus database entry for https://dungntc.com/wqgfjott/D7yFR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:543198
URL: https://dungntc.com/wqgfjott/D7yFR/
URL Status:Offline
Host: dungntc.com
Date added:2020-09-17 08:52:35 UTC
Last online:2020-09-17 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: bomccss
Abuse complaint sent (?): Yes (2020-09-17 08:54:34 UTC to abuse{at}choopa[dot]com)
Takedown time:6 hours, 39 minutes Good (down since 2020-09-17 15:33:40 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17jS2cIKMC9SQfG.exeexe 71686108c48c03d018671bfbc90e6510137bdd64b0e9f138cc6326bea891817cn/a Heodo
2020-09-17BK2jj5n.exeexe 9bb5fe40421cf77e4a0d131008c5ccd89d016481010ab6eb609b92e18b4287e3n/a Heodo
2020-09-17oG5I7x0UMQTwPklcBJ.exeexe 798e9f1e4e6ea9bb00ceaea72c6a3f7cf17dcb0006be1a81e1f42f0a46a1eb31n/a Heodo
2020-09-172.exeexe 4d74207ecac290ba2632ef04c0f3b7ad8f0a7b22ab49e52d0625e9eafefbdeccn/a Heodo
2020-09-17bk2qus.exeexe 0b970c467215a48b88aee1bdfaed6a2c337d203e2e05ad567d14b3f33d6f5682n/a Heodo
2020-09-17knHNFr.exeexe c1615fab18619a4f19d1b06656d364f6d79166ea07ee8231b6adae355c3e0b6dn/a Heodo
2020-09-17A1fd0d.exeexe 7351552aa32da015334a6c1a3f9bcbee4fae38b0a12593171f8e28e465b6a01fn/a Heodo
2020-09-17aLU3VkxiU4hTTS.exeexe f41e2ebcf731b5be58e971e3c4dc0f0710d5d0ac375b43407cf6a550a4f36586Virustotal results 10.61% Heodo
2020-09-17Qzyr.exeexe 66447eae933d0920e08b3b1783c00d93b106d4f9b0e2a30331d62e45a4d5b882n/a Heodo
2020-09-17W11fBrX6B0kYK.exeexe 22be35c89dad2b12fb8e1a8f41ac425fabd6851ab0e25ba11090c8224f31a507n/a Heodo
2020-09-17xQZxIz8H953ey.exeexe 78741780b03591c92a611f9644c0cb24b9ae19214ca3432d59d1dd564d5ac794n/a Heodo
2020-09-17PZJY7S.exeexe f57b45eb8bf059e0ce34373b6c87fe3d8d4af5812d4ebfc6d13cc8c3477ad7c3Virustotal results 8.96% Heodo
2020-09-17rFzm7g0.exeexe a0cbc4483d9c842dbbeeaa53f5e6f85ca29b10d56e3084f9c37a93331c92d6b6n/a Heodo
2020-09-17mVlI9XSouxIRMI3Q5EuC.exeexe 2f893a3a5964425460053797f657970f2030bb8add1610a07a2ab7bb7c7ce3f5n/a Heodo
2020-09-17sXH.exeexe 51222820784f94dde65541266c8126ed621653745cb54aa01ac4cb8c9c78ad86n/aHeodo
2020-09-17Ha8m.exeexe fe0b38cb2acf9c3a7d0d21d6613c1b309d88d73e4e4d450586eeb47631181ff2n/a Heodo
2020-09-17iUHmxC.exeexe 3012376cb706d777cab14575d112a33628d04712082db59c91984d16d9ffbe17n/a Heodo
2020-09-17tT66WheewxtjPOm6Y.exeexe 662419cbd62e25a55e4524460c0dbac8073a5f49cf7227bdcf2ff6289603def4Virustotal results 32.84% Heodo
2020-09-173OFbAuv.exeexe 1cc293a9701d08af1e02bb08e8b9fd7bd303c28443e6f6760f16ed998def79fcn/a Heodo