URLhaus Database

You are currently viewing the URLhaus database entry for http://hieujhfbnbxgasjd.dynv6.net/POP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:826484
URL: http://hieujhfbnbxgasjd.dynv6.net/POP.exe
URL Status:Offline
Host: hieujhfbnbxgasjd.dynv6.net
Date added:2020-11-17 13:21:08 UTC
Last online:2020-11-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-17 13:22:08 UTC to abuse{at}ovh[dot]net)
Takedown time:13 days, 1 hours, 52 minutes Bad (down since 2020-11-30 15:14:46 UTC)
Tags:exe MassLogger link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-26n/aexe b8ef3fec68aff9722b58d90a1419bcdf2bee13c131106443161e9763ce27ab32n/a 
2020-11-26n/aexe 52282117a4609bb974a03263d64416f65210d03cc8cba3ced16a5e90b9f31b6bn/a 
2020-11-25n/aexe 6c3e230390b890ac0864edb2b6f75939371a9fd202b3ab57c57c0b08034d22ecn/aMassLogger
2020-11-23n/aexe 85d37e778b87935b7cf08cda721089885e045e50444643074a22b53fa2446bden/aMassLogger
2020-11-17n/aexe bc36fa2314f4e45645af22ca75887b7b627de4a65bfd1d274f18e7fc1975c8e4n/aNanoCore
2020-11-17n/aexe 6e6132e3f3bc119adac878ba65475b581698e8dd7d2169f984bb5eb232f6b3c6n/aNanoCore
2020-11-17n/aexe 2a334d14ae9438d732d1b5867674d939c15ae839d6f144af805708474aebedcbVirustotal results 26.39% NanoCore