URLhaus Database

You are currently viewing the URLhaus database entry for http://stevenrgerst.com/articles/qons/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:181978
URL: http://stevenrgerst.com/articles/qons/
URL Status:Offline
Host: stevenrgerst.com
Date added:2019-04-22 12:44:15 UTC
Last online:2019-04-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: dvk01uk
Abuse complaint sent (?):mail Yes (Ticket DCU001292139 created on 2019-04-22 12:46:04 UTC)
Takedown time:5 hours, 39 minutes Good (down since 2019-04-22 18:25:19 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-22gW8PljxCD0UQ.exeexe 6a8dbbf53727f534110eae73f947a5cd932304de9a0d8ff5f875609f18f33d2eVirustotal results 19.40% Heodo
2019-04-22BbbZrsBH.exeexe b291e3b6b7664c3d0373528f4aecc3c55d9a7a0dd90372b389d070b9c5abdd93Virustotal results 24.24% Heodo
2019-04-22d8ef4hp7uz.exeexe 5efe6e5cd6db4c802c46dd635050728bcbb507fa0a25f12035dfed02c5a4e2afVirustotal results 17.14% Heodo
2019-04-22o6RxWbdFM63.exeexe 468070ffb4c63e8f66aa13f3fbfea642f9856d86b0c36595666b408c8b582befVirustotal results 22.39% Heodo
2019-04-22JOtKFXuFT.exeexe c9a38fbd05046487fbdf976fbb426fede64bc302b957d5f2fd1e22b8867261e4Virustotal results 17.14% Heodo
2019-04-22yqDZoryFL.exeexe 42cba1ed6f5341d174343fde220adb83d812c626677349fed811963d1c220a03Virustotal results 25.35% Heodo
2019-04-22kZQCQOnlWyC.exeexe 535def3486dfa8e905602d899d0ced2ee53f077fd095291a061f613866f15cc0n/a Heodo