URLhaus Database

You are currently viewing the URLhaus database entry for http://pegas56.ru/df which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:85583
URL: http://pegas56.ru/df
URL Status:Offline
Host: pegas56.ru
Date added:2018-11-27 07:06:10 UTC
Last online:2018-12-01 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-27 07:08:07 UTC to abuse-mailbox{at}megafon[dot]ru)
Takedown time:3 days, 22 hours, 53 minutes Bad (down since 2018-12-01 06:01:45 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-298313.exeexe d9f027a108069bc29662d37a740fc10e95a7d934648395db8665f17055ccf983Virustotal results 20.59% Heodo
2018-11-2938704052.exeexe e3b60fe46c471044d46462de8b2dfda807d75b36dc0a6938b6cf20f554042018Virustotal results 20.00% Heodo
2018-11-2809.exeexe 8cf92c0b4d06b40a81cd342682d4f11851dea0571b59ed41ee5368a1622a1d2aVirustotal results 17.39% 
2018-11-28958.exeexe 9074096f046de748da9f5468d8eb5def37ef223a00f68afe8453ce728f0790d9Virustotal results 18.57% Heodo
2018-11-28537675.exeexe fe45c1718d3cb436dcf9d71146e3279bbdb3d0166456d166e1bfc6b5f76cae39Virustotal results 15.71% Heodo
2018-11-2895924.exeexe 3fff9b668822147dfb51e835bcaf15d7237a3ddf9b65fb3761d51d995740ce68Virustotal results 24.64% Heodo
2018-11-28067.exeexe 4b2b0beef7ce5d00fa22f18fb5447c04ed945e3103a40eb8bc44f2d348a46631n/a Heodo
2018-11-28217.exeexe 392af47602dcb2ce2e59f990200fd0270c20907e0f3d59faaf204e11d2674071Virustotal results 26.09% 
2018-11-2802432067.exeexe 094192054aba8b24d222173e9e691579980b848117c28579f840ae44809f887cVirustotal results 23.19% Heodo
2018-11-2831263.exeexe 7d84ace71a8c3fe19e225030c34163c34f938e99268b1b2667d23a96c1b95e3fVirustotal results 20.00% Heodo
2018-11-2874631.exeexe 2763ddbc8c826c4fd517b6c7e3583f882f33269e2a1fe46292e02b65e7a3e578Virustotal results 19.70% Heodo
2018-11-289058842.exeexe d3d73984cfc1f9300234bc7a7870f97f8e48fc400c8744422357afe4eb1e7373Virustotal results 25.71% Heodo
2018-11-2865.exeexe 6fb9b93193ce451ff5d116404ca97d5ee746d4dc2e192857cd753e8b02690f12Virustotal results 19.12% Heodo
2018-11-279701641.exeexe 9a067d8df7747b04752c0b2b13b314afc63cebdedfd3c4e3250bd20a263af116Virustotal results 17.39% Heodo
2018-11-2703742797.exeexe 85cae354944da5e43bcdcf4a676ef8e7fb8fbd2716a5823c626486539274f614Virustotal results 17.39% Heodo
2018-11-2733469129.exeexe 0a46cd8b74669e5f6b7704ef004d1166115ec1a05481639efb84fa11ca14962fVirustotal results 5.80% Heodo
2018-11-2767413.exeexe 27d427aadee0e362b72f541f3e236b136bef133169c6d1d345f214e186ca147dVirustotal results 24.64% Heodo
2018-11-2727347800.exeexe cec010bf6f4c93eddb613dcc20c7f4e4159cc25410f20bf5e91dec4129cbefc5Virustotal results 22.06% Heodo
2018-11-2797019.exeexe b403e02bf02199caa81f5c8aaf32217371d8e2ff95163730421e80db11b1b21aVirustotal results 38.24% Heodo