URLhaus Database

You are currently viewing the URLhaus database entry for http://atkcgnew.evgeni7e.beget.tech/HkHe3fKTc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:105407
URL: http://atkcgnew.evgeni7e.beget.tech/HkHe3fKTc/
URL Status:flame Online (spreading malware for 7 years, 5 months, 16 days, 4 hours, 20 minutes)
Host: atkcgnew.evgeni7e.beget.tech
Date added:2019-01-18 11:31:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2025-08-15 06:29:11 UTC to abuse{at}beget[dot]ru)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-1529457444b7268825b17399a00ce19fcd9ecd6647b936f229c8ca2bb35ea4ca64.htmlhtml 29457444b7268825b17399a00ce19fcd9ecd6647b936f229c8ca2bb35ea4ca64Virustotal results 17.74% 
2019-01-18jwonbb8HJ6.exeexe 46286ab7852adc8cc09aa9097f063c2d0c5fab402126f0d0688f9373376bd7cdn/a Heodo
2019-01-18iwUxWIBNY.exeexe 2e4d3cf77a6027ed130bd30354ba64722aba1cede2b156a1341df16f5516d819Virustotal results 22.86% Heodo
2019-01-188dLJ644v1B.exeexe c3524aba4c3b593992e147eff7a8cdded09b1d2c0409a42febc267e7fcc2257eVirustotal results 25.35% Heodo
2019-01-18ADBDDgFNEa.exeexe af3c3c42f0a36e2b0963df7475b2c8f473b39397d881310ed3966a66cb2972d1Virustotal results 23.61% Heodo
2019-01-18mSdyuwTlv2.exeexe 07988cb424a21ad690cdedae338b7b0a4e80be37a5930e3753701d7bacd4e268Virustotal results 23.61% Heodo
2019-01-18Ch1FdrGnRM.exeexe 8a60dc9876ad042a6c957db6414918f33b932aa1fa0bc56799100968d2a992abn/a Heodo
2019-01-18rgdeXf09.exeexe ee93d002cdc0dd18df0d0fc664c872d242d5f65847816f39e2483ee51ada15d8Virustotal results 24.64% 
2019-01-18GbtrkpOMlh.exeexe 7dd6da158e2dabf19aebf2a8c26b63869b25cea4a3c442573f97d5003d72da8eVirustotal results 22.54% Heodo
2019-01-18eASCckfJ4a.exeexe 9fa8b87ced8b5e051e51210ed34bb58af7c27617f9b20f39cda4551b8c13acf5Virustotal results 21.13% Heodo
2019-01-18819o0aVXf.exeexe f1516b1c8962893cd2e6da611f7857ff2e04a01040719b3306231a6cca80a9e1Virustotal results 22.54% Heodo