URLhaus Database

You are currently viewing the URLhaus database entry for http://cbmagency.com/wp-content/WjZV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:169006
URL: http://cbmagency.com/wp-content/WjZV/
URL Status:Offline
Host: cbmagency.com
Date added:2019-03-31 07:18:05 UTC
Last online:2019-04-05 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-31 07:20:06 UTC to abuse{at}ovh[dot]net)
Takedown time:4 days, 22 hours, 10 minutes Bad (down since 2019-04-05 05:31:05 UTC)
Tags:emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-31wPaPehFbJrb.exeexe 1bbd48c8587fe5c37d1d52bd1cff448ec40051048e2ffb074e3447277fa079ean/a Heodo
2019-03-31as7eVI33NI.exeexe c362fffaa736d22773363220796875fdba1311730534690ac58e1831fd1443d1n/a Heodo
2019-03-31yPDMOgSeT9v.exeexe a5b3784db26a511f61ac7e5a967b15ddc561a85f16c149b203526016c4b5d4f9n/a Heodo
2019-03-31bSmsmxkko4.exeexe 5d0ade1ab9f47d723b1dc3fdce23f5c043b5310cc33bb3a0b68d6fa5327db2ban/a Heodo
2019-03-31pdhHZWHLA.exeexe 5bb41f9204c1009dbf8c89179adbda10e5e4b5b4fe0cc0632f987e1715dacb69n/a Heodo
2019-03-31St3A6YJxV.exeexe 909593fe36e6300eb8557704a5d18d882008c1da8d7b8150e86b51631d77ca7dn/a Heodo
2019-03-31GtC7hnjRhcgI.exeexe abc421be83ad35e0b1d2b3d54432f86c28a742cee0ad92a70d235bab76d45ac7n/a Heodo
2019-03-31XUG6KfhERRvA.exeexe 2b07b8344b3e7715d2d1d7340cf32e7edf763bf2219d57cd502c475e937b7f09n/a Heodo
2019-03-31Jr9nHqM9kRH.exeexe 6b1ec694bf5cc9864391736e3ae04abeee18860d4ec0d933e34c2156d6043a23n/a Heodo
2019-03-31rvj3ZxXX.exeexe 701a301e9d13fafdf8027bd312a0d979bc1739c8136fed6d872c26820c2b42adVirustotal results 46.27% Heodo
2019-03-31pFmgY8gZ.exeexe b47436c6703e92516f65dfbe1902f5ce05f8f4edc5ceb617c24fdd557a843ee6n/a Heodo
2019-03-31Fi7su8w0.exeexe c72a6802c4f1b74472f51a7e93ba6ec5490d8af913b2e077f3eafa1e829889e7n/a Heodo
2019-03-31wDWlaV7n.exeexe 058d2f7f5cafbfa2e2dea5ad9446cb774b97136b9cfadad1f88214ad90452c9en/a Heodo
2019-03-31OLMy0f1de2B.exeexe a1b4dd88cd04017e7df10a3c59e7fd90d54a620dc76631e361d7a30702bd6d9dn/a Heodo
2019-03-31oFw1aLUk3p9S.exeexe c9f275801335fb28cc2bd0036d57d9201ad2c1c3bd7df471ff9541ac50ad4d5en/a Heodo
2019-03-3109R99qKKitf8.exeexe 5e841fbad41306403dee75f3d974ea518789a6d056eef414d7eebfccf7afabaan/a Heodo