URLhaus Database

You are currently viewing the URLhaus database entry for http://mktf.mx/ctg/g_pT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:180023
URL: http://mktf.mx/ctg/g_pT/
URL Status:Offline
Host: mktf.mx
Date added:2019-04-17 23:55:35 UTC
Last online:2019-06-16 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-17 23:56:09 UTC to support{at}webnx[dot]com)
Takedown time:1 month, 29 days, 23 hours, 23 minutes Bad (down since 2019-06-16 23:19:54 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-19Asw_e.exeexe d6798b62cef08c4f61a30dfa346faf5aa29f9d03e4599ebe5ae910a193087b86Virustotal results 31.34% Heodo
2019-04-19I_1VQ.exeexe 9cf320071b2c2a718575e5eca7ece66ec3a85b84a8b7e932656cac98265f6902Virustotal results 31.94% Heodo
2019-04-19p_8d.exeexe 4aa0d416787264f62a642e716f6497fd12d05b7aab09f6c048185af4bb8835b2Virustotal results 28.79% Heodo
2019-04-19Y_99N.exeexe af9d20112fe0c70fd621badc3a9d5947cdc2892f044bb928854d47447bd2338bVirustotal results 25.35% Heodo
2019-04-190LO_ym2.exeexe a3f7664451fba95ff734f75331eba03e45f12ff2f7c079cd8301585ae5baf507Virustotal results 23.88% Heodo
2019-04-19N_GI.exeexe f2899955a9b359550a71ce73036feb4d909e36a4d75690f8710c8beb67cdc4b0n/a Heodo
2019-04-19t_n.exeexe f80e92e1672ccb1dcf58236b2f4c6ecd20d0f5835025675d3bd858e44e69cf42Virustotal results 21.21% Heodo
2019-04-18yh_zi.exeexe b3226a5b03c0beff93b18fa928b1664d3c88e13280d186b5cc38fb5813615f08Virustotal results 20.83% Heodo
2019-04-18F_Z.exeexe 93faf9052ea0c2808e9ab2a006a991628787c895fe955c9745872406d92e44b6Virustotal results 15.15% Heodo
2019-04-18sEr_yy.exeexe d2a58b69ee0ce1721ffe810783f30a1567592325eafff8a1f64a8cdd331cdbe2Virustotal results 15.15% Heodo
2019-04-18m3y_0.exeexe 8156a662d50164a0bdf33a371363dbcc46eea9f8d99e16b175b4c8cb5ffd26efn/a Heodo
2019-04-184_Q.exeexe f24f10db6d85e3e4c23fedb988f8ae9935214087ee20e53b1cc3e9b1bbc89109Virustotal results 12.12% Heodo
2019-04-18B_0zl.exeexe d70006e5105cf49d36cc24d6bcd92eae4d33eb6097e7f10037aee2c8e97d7048Virustotal results 10.94% Heodo
2019-04-18Z_I.exeexe 53852cdd1fe3c7b5a89305ae29a01a7aa0aa24c6b4dda66a06123cb26e6733c7n/a 
2019-04-18QAR_99.exeexe 812509e564caa12c80e472ddb51c27eafe0bb4a9a0172d4b764d55ea92bbab34Virustotal results 11.76% Heodo
2019-04-18I0_ll.exeexe 9588692f5a1b07b834c85e7d169d343acc12d04d62ddfb50f82aba8de05ab9c0n/a Heodo
2019-04-18Db9_9MB.exeexe 3aa16d82097532765d6ff092370548eaa58183e09f30cdfd5466cbb8465febcdVirustotal results 12.33% Heodo
2019-04-180w_SO.exeexe cbde0927defab85a55aeae70c047fc937b9464c22e9720099a445e0cb4d28f5aVirustotal results 11.94% Heodo
2019-04-18ia_Egm.exeexe 4d72881474f61af7d369cd027f1f301eb0cbd5e3ed01aade1648cfd8e13ea61dVirustotal results 18.06% Heodo
2019-04-17FBO_TS.exeexe 08496cc999257f967a0174a1e24876753ca8ef069eba9a0480755389b6acce89Virustotal results 19.70% Heodo