URLhaus Database

You are currently viewing the URLhaus database entry for http://mazzottadj.com/wp-content/CYB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:159840
URL: http://mazzottadj.com/wp-content/CYB/
URL Status:Offline
Host: mazzottadj.com
Date added:2019-03-15 07:43:12 UTC
Last online:2019-03-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2019-03-15 07:44:02 UTC to abuse{at}iplan[dot]com[dot]ar,abuse-iplan{at}iplan[dot]com[dot]ar)
Takedown time:6 hours, 24 minutes Good (down since 2019-03-15 14:08:16 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-15l84CwuPZyG1e.exeexe fc2c8bfbaf45615f4020978d7d0f36c0d532536f763660e3fdbb8b842fc25486Virustotal results 20.00% Heodo
2019-03-15RuMqHp2D.exeexe d8e1a836f3fa6ec77f5d1bff1715f37f8c3d36b6ec4fe482db9b5411b0281fe0Virustotal results 18.46% Heodo
2019-03-15EUHikQGBw8Mo.exeexe 3ae4cf277910142997f70c63ce76b91e1f095d408707022b4aac32f385e888a7n/a Heodo
2019-03-15SoGGbz8ukb.exeexe 5b65ed88c46d2efcb822da245237abae3141afd7ce47b6d44073031e1746f2d4Virustotal results 18.46% Heodo
2019-03-15y09n151nFo.exeexe ea2965d7661202c2a1d3025263336f03b45dbf928930a2052d7172ef1126b5a9Virustotal results 21.43% Heodo
2019-03-15ZMU3H6H7b.exeexe ad019869ec7fca3a7ad57d337fd4a54f56fb663c9f67407479a0ec835247565dn/a Heodo
2019-03-15kHaqwxuAjSs.exeexe afdd0850bbbd9878308fca1a981e388d04420e3a68ee91ef01f28452f7bcabd9Virustotal results 36.36% Heodo
2019-03-15A5oayYbl.exeexe eb4aa88d7332854ab72f3e0978cbc51e479b6be97eb8efdd8086e00ec39c4c9an/a Heodo
2019-03-15EzKSMIUj.exeexe 68cd7fcbff591939e49a86a42f568068d0740719e74c7ee54c78c09a15500791n/a Heodo
2019-03-15yM043H8vTC.exeexe f1159cc147b3c2fdbf659e7f7a714fc86186f638660c5cf459ed7db86bebec68Virustotal results 27.69% Heodo
2019-03-15NhgZgNF9Va.exeexe 5524e5520899204df143a853bd7162817854563f5eb7abd7fd83e59bd7fd1468n/a Heodo
2019-03-159BSvH8req.exeexe f2a56535841392831b9e46014c7078ee7dc75e741000d103c1aaaa19cc3f8b55Virustotal results 32.31% Heodo
2019-03-15h1WeG5N4P.exeexe 3cb301babaefdb9f2a505a179293b4d3fdacaf3e2ea0040e0f7a44d5b695a306n/a Heodo