URLhaus Database

You are currently viewing the URLhaus database entry for http://gooddns.ir/donpyx/donpyx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:770564
URL: http://gooddns.ir/donpyx/donpyx.exe
URL Status:Offline
Host: gooddns.ir
Date added:2020-10-30 19:23:04 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-10-30 19:24:03 UTC to noc{at}dedfiber[dot]com)
Takedown time:11 days, 5 hours, 13 minutes Bad (down since 2020-11-11 00:38:00 UTC)
Tags:AZORult link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-04n/aexe 0fd52c8b8586dfd283eb2b6acac20ed36b7887e56131bad25a61f29e321e13fcn/aAZORult
2020-11-02n/aexe 9739e405c8408179997ac6d497f557afad062cd201d0155aeca09386b35efa60Virustotal results 56.94%AZORult
2020-10-30n/aexe 4a126dd572e4e9683ee2c10df9415488da67ba17fb5319082af4f89ae8224a5fVirustotal results 37.50%AZORult