URLhaus Database

You are currently viewing the URLhaus database entry for http://dandyair.com/font-awesome/rOOAL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:556124
URL: http://dandyair.com/font-awesome/rOOAL/
URL Status:Offline
Host: dandyair.com
Date added:2020-09-18 14:30:10 UTC
Last online:2020-09-18 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 14:32:07 UTC to abuse{at}digitalpacific[dot]com[dot]au)
Takedown time:3 hours, 41 minutes Good (down since 2020-09-18 18:13:11 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18TGt42wX2TlYfVPvccrrj.exeexe 11293227e278e7badef5dd1ddc0f888b8ce856e97c47845f0fabd167c75d03f1n/a Heodo
2020-09-18c1E.exeexe 8abca8113846fe5ec6cdea8a2cfb089ef7fd7026feace2e977a609b4a0fa5092n/a Heodo
2020-09-18907bIxUX8MIb1XDN.exeexe b12f644691f036923bcb474504aefa28d68c9799ff1da1e73f2c59a6f45e3345Virustotal results 8.96% Heodo
2020-09-18HFpyBMhDTkS.exeexe 628e7fe11805e41cd9fc545a2b89d0ce0cd3e987951c52aed5ee682313b82f45Virustotal results 8.96% Heodo
2020-09-18oq.exeexe 9a19404e5648b71c24f9a2e2f079ec1eb8c76d0ed077cf22cb1e25ee9dbd6a43Virustotal results 9.09% Heodo
2020-09-18F.exeexe 8aab93838a7c85b236ea9339991062cf1f39dde0490761273e1aadeef665c611n/a Heodo
2020-09-186GSqw4HmfLscYcN5jya.exeexe 70d0961012531c63d64053e7649085c42423bfce581ac9235337dbf59a52d5dbn/a Heodo
2020-09-189xIuA8LnQdw.exeexe 9078e7d994c02cf458f0853b8da50eb6481467e52b681a622e6e80a4d5e59948n/a Heodo
2020-09-18HT.exeexe bd0a1939dc10f82875cfe28d4204cdac12ca0a1815898b400ac7ef89425d1d39n/a Heodo
2020-09-187.exeexe 32068b46de151ce4741c3d109584dd43b6affb49068f3ae55438abf31c932bd9n/a Heodo