URLhaus Database

You are currently viewing the URLhaus database entry for http://2n79.com/ywr1go.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:980255
URL: http://2n79.com/ywr1go.zip
URL Status:Offline
Host: 2n79.com
Date added:2021-01-27 10:41:26 UTC
Last online:2021-01-28 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2021-01-27 10:42:45 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 day, 8 hours, 15 minutes Poor (down since 2021-01-28 18:58:17 UTC)
Tags:dll Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-28n/adll ff0efdad65d67bb34986f4be712f63ebb994dfa2fbec699a5ee2693688be6463n/a Dridex
2021-01-28n/adll 834b8d8260559279876705f391670c007ee66014a2d8107abbc03abed330495en/a Dridex
2021-01-27n/adll 3526e341355ced713307bd2660df457b4ede304c0fa7f2f90b5d5b0a65ebc5den/a Dridex
2021-01-27n/adll 5fc8b21e4976f8210d3b9ab1f9400a0fcabd720f1c3611147daa72e9a8e5624an/a Dridex
2021-01-27n/adll 799df1093a5c28e4852f263e98c6c0d7a5cacf07cde3131e3b80e809a269136en/aDridex
2021-01-27n/adll 029ae6ff82c941c83049b7387d1d3f367077e9c27645e2c951ac8a9f8ac51d5bn/a Dridex
2021-01-27n/adll 609bdf4a236231539cc2ed813319888615c646eddc20e2b559efa0e6e236bff4Virustotal results 11.76%Dridex
2021-01-27n/adll fc8724525d089bab1e6259f660fd4a36f7e54caf2aa3a39410b858381af8dabdn/aDridex
2021-01-27n/adll 15144d693b83175b6dbf9e9468a33660aa6ab1f29a2650c945993af8031779c6n/aDridex
2021-01-27n/adll c23f0ce9cd543a9cadf9a5f0e92e30fc99e90a38e9d2c8130805b2902de30d35n/a Dridex
2021-01-27n/adll aca6dadc8cf23497c48a11899481945920a62edd3568f5d0c67cf96e11543ee0n/aDridex
2021-01-27n/adll 0f01c106b972cef05b8321dee61e67b60a00ab0851310c9408aada482bc491b2n/aDridex