URLhaus Database

You are currently viewing the URLhaus database entry for http://igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu/OSW.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:780207
URL: http://igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu/OSW.exe
URL Status:Offline
Host: igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu
Date added:2020-11-02 18:07:06 UTC
Last online:2020-11-11 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-02 18:08:10 UTC to abuse{at}ovh[dot]net)
Takedown time:8 days, 20 hours, 7 minutes Bad (down since 2020-11-11 14:16:03 UTC)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-11n/aexe 4ef9ce3e9a540b8095c436454b0cc9d5dc5be454f46d27e90cf404e02d0d1effn/aMassLogger
2020-11-04n/aexe 119106aeac2ed36c440f01ce5b1cdd3baca8f1d2484a4f9bbc35228e5236b692n/aMassLogger
2020-11-04n/aexe 322cdafdbecbb10cebb964011c87d6c5fff3951cf2b71fe3cf9e92636ade84b6n/aMassLogger
2020-11-03n/aexe 657ce0145781e930d93e0cf3953390f98f22323be721a6d44db6342a44aea27fn/aMassLogger
2020-11-02n/aexe cc0a089658a684db93cace34d85bbbb94d3950425517ec12fd41ea620822bcf2Virustotal results 35.21%MassLogger