URLhaus Database

You are currently viewing the URLhaus database entry for http://shazaamwebsites.com:80/wp-includes/18/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:155062
URL: http://shazaamwebsites.com:80/wp-includes/18/
URL Status:Offline
Host: shazaamwebsites.com
Date added:2019-03-08 17:17:16 UTC
Last online:2019-06-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-03-08 17:18:06 UTC to victor{at}corporatecolo[dot]com)
Takedown time:3 months, 12 days, 16 hours, 21 minutes Bad (down since 2019-06-19 09:39:52 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-09HfP.exeexe 92452e74ecec8a7a041c2284dff97089c76a1fa34fdec9ea86d054c45e5924a2Virustotal results 16.92% Heodo
2019-03-09kGz.exeexe f0af67893783b466c9e53852717feee9193249d4528bbf4a9cb4c4fb7cfb91e4Virustotal results 18.31% Heodo
2019-03-09IeH.exeexe 7a926b2db3e0cbf707e4cf26a4c18768c5c58ab4622f9151a1b9da86325d3ac3Virustotal results 20.00% Heodo
2019-03-095A1Tj.exeexe 1633f3d7b587b98d99657be8619986f66a04b47ccce86c6809bb3d5c78bb68d3Virustotal results 35.38% Heodo
2019-03-09WOpg.exeexe 243da77c89dcbb25755d04a92ca4a37e77fcfebfa27ce4750a9944af894e44d8Virustotal results 34.38% Heodo
2019-03-08tio.exeexe 59d735fc628387383882c86d5c7b4317d0a2fd366d5ce445bb0200fef2bacebaVirustotal results 34.85% Heodo
2019-03-08Iiw8M.exeexe 2a9ef8a2b0902fa0b03f5a5e71919085a1e3bdaa7fa5c321457795be13358161Virustotal results 32.81% Heodo
2019-03-08pYg.exeexe bb76260795e829d02c40f8399be33045489661f0deacaa7ad923fedfec195420Virustotal results 34.38% Heodo
2019-03-08ycSV.exeexe 97f3d6d837f3810a43f5c94c19fb200500084198a9c0bd807957dbebc65be411Virustotal results 32.31% Heodo
2019-03-08bidm.exeexe 7e4c7fc90400694645a4779f8f3583936df5fe49a11cf3d0006509ba4cc5cf18Virustotal results 30.88% Heodo
2019-03-08jLPa.exeexe 03ca735a3f8fbea8e542b60f01e6f933806b9d3a1060a61689a0da32a2188a53n/a Heodo
2019-03-08o56zll.exeexe 9742ee1b34506214e3d42cb68730a24a426390fd514ec17f884b1e6e918e94edn/a Heodo
2019-03-08hoXJB.exeexe 65fea36b8de932fb3c2ccd760d8589b064c60e9d028c9ee291f792e88cb16a2eVirustotal results 30.77% Heodo
2019-03-08P3tx.exeexe 86d6087f270065837e4b59e5ce93b788d8e8b63f205efe716c990d513cc35326Virustotal results 26.47% Heodo
2019-03-085szyC.exeexe 48ce1e3c99e2b2ef6151127f43aae19b89a686fdaeaab634d5c769054080e103n/a Heodo
2019-03-08fgNQVG.exeexe ebb5a04f7ae81aa6bcda2f01c3145d09cab9255ac434defe1e8bbef44016026an/a Heodo
2019-03-08lQ.exeexe 841beae89f53791d81e35514c0c6f4aabc8bbd57eca1cf792c40455462ebb007Virustotal results 21.54% Heodo
2019-03-08q18fjt.exeexe b46891a722d302b90a9c09d4960364e1722dd406b045e665ce22b992d73447a0Virustotal results 18.75% Heodo
2019-03-082No4A3.exeexe 8244d64d8f54af0c09d267260b564ca355ff797b9b750dd5a6c805fc7f896639Virustotal results 19.70% Heodo
2019-03-08NH1Kb.exeexe 75fe32304d9493dc2b95f24c2d86c24cb03395a7761481e2bc8743b58448b1f2Virustotal results 21.13% Heodo
2019-03-08lI4I.exeexe 9890a2f1b8fd14398e89b068da067db0a471174fd7e9b76c7af105c459b1a71bn/a Heodo
2019-03-087d.exeexe b1f3df1ee50590110969c0fac9f1cbdaa1c6877b6e4e12e3c4fcacc7c312bd2fVirustotal results 21.54% Heodo