URLhaus Database

You are currently viewing the URLhaus database entry for http://119.28.135.130/wordpress/l_Cf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178457
URL: http://119.28.135.130/wordpress/l_Cf/
URL Status:Offline
Host: 119.28.135.130
Date added:2019-04-16 08:03:18 UTC
Last online:2019-04-16 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 08:04:05 UTC to ipas{at}cnnic[dot]cn)
Takedown time:11 hours, 20 minutes Good (down since 2019-04-16 19:24:38 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-16ggy_p.exeexe c1fb0eceaab0ce12e69f4ad1d507fdeb4938c035c34569cf6853f3a5a01d72e5Virustotal results 11.94% Heodo
2019-04-16eD_CWZ.exeexe 8827dc4d23f77a280e8ac0bde3af229d16e7b5c82dd46723ab261f43675026e1n/a Heodo
2019-04-16C_i.exeexe 36c85aa96e1c5faccec2c07418a81137ce1b95abce60842b1219a9ede6a0463fn/a Heodo
2019-04-16N_DL.exeexe d311c24d74572a791025133751fe4128acece91f5a9853bcc5b02e97e8380efcVirustotal results 28.99% Heodo
2019-04-16CjJ_v.exeexe 2d8637e6f982f124983d1e8f79406dd57be80104fb528681f0271cf85bc9e452Virustotal results 28.79% Heodo
2019-04-16b_T.exeexe cbe2094125606d2c0b42609d4c676c449dd88e04d21bf14b9452b81a17d9bfb5n/a Heodo
2019-04-16vGF_mk.exeexe 5a88abd439bfe2e1154e687a23e948c522a8001eb03625a13e5d49323cc37e6cVirustotal results 28.79% Heodo
2019-04-161R_go6.exeexe 109e48b2870b4aad574a186bf09a5de5f669abf8fa45b928a7dcc8e2a33bdf56Virustotal results 26.87% Heodo
2019-04-160P1_z.exeexe 0d5caee37f741e52747b39d4bdf290ea9c1345ab186217fe2508066fd75eb54bVirustotal results 35.71% Heodo
2019-04-16R_d5.exeexe c4c49c07fbe17034954cf16db089b3757c0b05517e15737bfbcb18d1c73a4582Virustotal results 26.87% Heodo
2019-04-16VKx_R9.exeexe 6bf96b15dd77bd7250b402599f43235d42b160551003886a289d4859bb545865Virustotal results 25.76% Heodo
2019-04-16b_pSM.exeexe 0a86ffa10e35bae1332020fef326cc1ff914a92450c4d19d2a65a4670495f8een/a Heodo