URLhaus Database

You are currently viewing the URLhaus database entry for http://haeum.nfile.net/files/haeum.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:111691
URL: http://haeum.nfile.net/files/haeum.exe
URL Status:flame Online (spreading malware for 7 years, 5 months, 6 days, 8 hours, 16 minutes)
Host: haeum.nfile.net
Date added:2019-01-28 03:26:07 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2025-04-27 22:27:08 UTC to irt{at}nic[dot]or[dot]kr)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-27haeum.exeexe a413ec38b5d2286aed07546206e1438dfc406b1f42a8c9d722cf6e3c226c7ba9Virustotal results 35.62% 
2019-03-07n/aexe 807ac597a0790a85c54e3054c813528a77ccddd5d25e1d1187d5cbdf911e73bfn/a 
2019-03-06n/aexe a0f7b62809d90bcc00b02c45cbf25fc5a34d77cdf85449107cea6012986a6e16n/a 
2019-03-04n/aexe 7d5605adafd7e96773fd0bac70a505cdf1ff17635868f287cf67c38c2b0d2bban/a 
2019-01-28n/aexe 8709f3c69c46612a2024f3479e882e2f856fdf0164d0797301d8b6b8151f5bc9Virustotal results 63.24%