URLhaus Database

You are currently viewing the URLhaus database entry for http://daugia.org/laamspd3.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:823471
URL: http://daugia.org/laamspd3.jpg
URL Status:Offline
Host: daugia.org
Date added:2020-11-16 14:02:27 UTC
Last online:2021-01-08 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: stoerchl
Abuse complaint sent (?): Yes (2020-11-16 14:04:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 23 days, 2 hours, 41 minutes Bad (down since 2021-01-08 16:45:19 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-17n/adll af3c57b18d35f88f076c5b15fd7cc814d4e7724037158d7e5a3facf9bece3d26n/aDridex
2020-11-17n/adll 6d5ca5fcaba6a6558013344ff5f11328e8079540e8ebe95789d9c185e11f8e44n/aDridex
2020-11-16n/adll fd6f6c377f403f5faccf5c4bb03a0d5af94f7f57ac13572a42b187cdbda027ccn/aDridex
2020-11-16n/adll 8cc5a65a8206e82d93604182bb6cd7f72e08a6b45cdf07e6479e493457c0ab12Virustotal results 26.76%Dridex
2020-11-16n/adll 881c022032c6fb9bedfae76dd6c93863b2b7f48e282e0dbcbdcf702a6958ced2Virustotal results 29.58%Dridex