URLhaus Database

You are currently viewing the URLhaus database entry for http://baatzconsulting.com/wp-includes/Uyfww/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:162701
URL: http://baatzconsulting.com/wp-includes/Uyfww/
URL Status:Offline
Host: baatzconsulting.com
Date added:2019-03-20 08:01:09 UTC
Last online:2019-03-20 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-20 08:02:03 UTC to jeff{at}sudjam[dot]com)
Takedown time:8 hours, 22 minutes Good (down since 2019-03-20 16:24:19 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-200heVyyNFpDi.exeexe a3c49cbfc7e1f9fa1e6936f997c74f938637e3a43e084c049052c06aa65e462dn/a Heodo
2019-03-20qKNJ9xvm.exeexe 2a2cc7261ac4a995e8a9cf5d02993cba0bb1fdab4732d3c9858ac65c60d27a2fVirustotal results 13.43% Heodo
2019-03-20BLUkE4756dY2.exeexe 0c6d405e1ffff998f7315774f9c194d6ac153c111820950c42ab3b9bb975dde8Virustotal results 21.21% Heodo
2019-03-20vVhpKg1J.exeexe 83c97e0fb9788f5715bd3c98b70c423ae23920f2217c36cb015254a66b6dac2an/a Heodo
2019-03-20PboYvs5S5.exeexe c522cf5f9d3a3a727479798745e5c788a79a56cd7ce64973c1445ca79d6a6397Virustotal results 23.94% Heodo
2019-03-20mVnT9aVzomMs.exeexe dc781f5cc5ee01a4b3c27915f5dde82f0a733f6b5d9aeb8d49f6613ab4a9a381n/a Heodo
2019-03-20XDo0c2GkVu.exeexe 4f82b189d1d0a051091f53642933798c4743c5a7148119a0e5dca8910158c399n/a Heodo
2019-03-20KCa1C4w7p.exeexe 0fea6355e3f277a1cf6fd238a405e322cf48400324c857c9e84bab53f922d398Virustotal results 20.00% Heodo
2019-03-20p78uwdxzHhd.exeexe 06d5d2f7e9020d83e4a7064b9c681f5087991d2c860a44bc96a283b880dc9841Virustotal results 22.86% Heodo
2019-03-20Ha336IoQ2KO.exeexe ac826ec5b32596a660141be5d248233de45c735032cc9f9f24dc37fca59685d3Virustotal results 21.21% Heodo
2019-03-20Le0RkQPA.exeexe 150fc1b13ad29c3afcf178b9a48542f6944a67c43cd3df339f725999359c0f9fVirustotal results 24.29% Heodo
2019-03-20HiM8AQ0r.exeexe fe85849505914fed75fedb7eef7b19b9bfaa813a1d1d82bccbe8b952c5d2dd12Virustotal results 21.54% Heodo
2019-03-20AKtVgj2DoSo.exeexe 504e2c75617553d852df04ff030d829e7b9f3dc82595d2d224ee1c35b0dc24afn/a Heodo
2019-03-200OU4nSlNiCi.exeexe d608da59f873a2fdd5136ea2a56e3667f26c9c9c775fa33930c36ce081026d6aVirustotal results 38.81% Heodo
2019-03-20PxGEumphrk7P.exeexe da7cc6342217ae29474ef0842ae340be932685a198587ceceaa85c624fe5b600n/a Heodo
2019-03-20ptVqAzU8X.exeexe 080a5776eb2680f2673b0aa71dc3b30e5eaf08d4c9137a4eb3b26668d5a4ddbdn/a Heodo
2019-03-20jf3MJ9iDI.exeexe d7b8c87a64dfab6e23a98b41b710c38156bae35139400522bc03e8daf544fd86Virustotal results 34.85% Heodo
2019-03-20YCeGTTwhHi.exeexe a2fa811a7f98898b639ad06ad1f4c60f315e20a683a7fd964c3eafc1b18320c4Virustotal results 30.30% Heodo
2019-03-206GS3pgeHsgcC.exeexe e7cf64f1ffd24569a02fc9ea5cd0d65f8c7d4d68923787b5d9a365baa8ba3710Virustotal results 23.88% Heodo