URLhaus Database

You are currently viewing the URLhaus database entry for http://dingesgang.com/7GDHCHEW/PAYMENT/Smallbusiness/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:60058
URL: http://dingesgang.com/7GDHCHEW/PAYMENT/Smallbusiness/
URL Status:Offline
Host: dingesgang.com
Date added:2018-09-25 01:09:03 UTC
Last online:2018-09-28 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-25 01:10:02 UTC to postmaster{at}myhostcenter[dot]com)
Takedown time:3 days, 0 hours, 9 minutes Bad (down since 2018-09-28 01:19:28 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-26PAY #26CYHJRX.docdoc 9a65d3ee50eca9eeddf21fd756ae26fde2e4afe443f78daac7ee8f101bb9b387Virustotal results 31.67% Heodo
2018-09-26SWIFT #80YUP.docdoc c9165681d8e493148ddcdd556ccd935d2849ab5034ee7cf546aa26eaf4993a17n/a Heodo
2018-09-26BIZ #41JCVHHD.docdoc eb1c148714c8facf2bba812b43ce2056726d02cd8e478157c1b70e3d36805912n/a Heodo
2018-09-26SEP #28777CRQI.docdoc ae1f0ba2a5b3e728112a6d2d90fac0971d86c58a46470e1faa9ca3bb7f1a89a9Virustotal results 35.00% Heodo
2018-09-26PAYMENT #6502SDFZI.docdoc 580c61b5ae55fcb2e67d0df00131d48c415727e09780bbd3a26e078d6cf33d49n/a Heodo
2018-09-26PAYMENT #4544156KKIEWOR.docdoc d806e3cbbb867fc232274542ead539d002a2dc4ced366f641068af7444c1c58bn/a Heodo
2018-09-26PAYMENT #312KQXCXO.docdoc f2e1fc34098cd3282179c33c428c5f0f15c0f63fbcc77a451bb170f93a114999n/a Heodo
2018-09-25SEP #44TVLFRQA.docdoc 66fdf0512f384acefc9494c0e656a86e8fbd9b29e5d3b4d36c8eb0c09cdb3b8dn/a Heodo
2018-09-25PAYROLL #3220913DFOUL.docdoc bf858761c298da7957e67f1f65e167c312d3e13cef3f89da7617aebb17875d38n/a Heodo
2018-09-25PAYROLL #892647QBUBZW.docdoc b941ab911bd56a59be6a4c31d1eea8baa71643836a97c376e98014444036e2fdn/a Heodo
2018-09-25SWIFT #99164ZZLPJ.docdoc e6048063142cbf76836ff584dead136ed7724ed97ab066bb97d9811a8282a6d3Virustotal results 28.81% Heodo
2018-09-25PAYROLL #086694ETH.docdoc ad6910539d7a43efb2ded874a59dbbf5206fac6f450faa3db013adb9c7550590Virustotal results 27.87% Heodo
2018-09-25PAYMENT #7628825ZLQ.docdoc 5dae6afa19ac18673983b870273a0fe3016ed0c0ca1b0614d540ba5ff85579fbVirustotal results 25.00% Heodo
2018-09-25BIZ #12PINBJQ.docdoc 6db563ccc931c797407071ce0c7ef73c881fcffa8c9fcfecb1519172964c3b93Virustotal results 21.67% Heodo
2018-09-25SEP #43KFVPGJAQ.docdoc fab645b1451af64d0c0c8bf79b322fc249d5ac8451bc09a4dc1addb23cdc532cn/a Heodo
2018-09-25SWIFT #5172528VCU.docdoc d7610008f1f0825a0d6e0eba01ac358d9f553c19db572c42622b2c2e520331a9Virustotal results 20.00% Heodo
2018-09-25SWIFT #365FYSRKGWW.docdoc 7bc23335685fb4ab8955cde6aa243ce6a1b8171fb0e82c7e2ba659e3d9c13653n/a Heodo
2018-09-25SEP #9947177WSSB.docdoc 3c77249fa8b6cfb58129b4952f0f9115fcb493c9627e1a277a5461c40479eb96Virustotal results 31.15% Heodo
2018-09-25PAYMENT #9166076AXKPS.docdoc 2feaf66901fc4e273f6f7aa487eee7bc772cf18631cefc2124f9d9665eda530en/a Heodo
2018-09-25SEP #412748XYVMTC.docdoc 0e1b7ed637ae78589d7cdd409c583953a3f31ea58c1b493ae78756c28a66b878Virustotal results 27.12% Heodo
2018-09-25PAYROLL #0843824LQ.docdoc 1dd1c37656d733eaeb78adccf129b66def70eb89c9754f0120c5db96f0f4864aVirustotal results 24.14% Heodo