URLhaus Database

You are currently viewing the URLhaus database entry for http://eiamheng.com/EES/F_bi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182387
URL: http://eiamheng.com/EES/F_bi/
URL Status:Offline
Host: eiamheng.com
Date added:2019-04-22 23:37:06 UTC
Last online:2019-04-25 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-22 23:38:10 UTC to op-network{at}inet[dot]co[dot]th)
Takedown time:2 days, 2 hours, 7 minutes Poor (down since 2019-04-25 01:45:55 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-24E_NW.exeexe 085e6a56fdb7daef2203942cab25721e40c92fc74846a1ba1278afc2c1601a4bVirustotal results 26.09% Heodo
2019-04-24BH_4.exeexe 3de3f82ba6763b3d6b09dea9b7b1badc7d6fb8af4a90eea4689055911f3267ddVirustotal results 64.71% Heodo
2019-04-24p_FG.exeexe a9f333b29971aff0de5b070be765e3e81135f6477f02afba879bd2638183d563n/a Heodo
2019-04-24Xuh_Tj.exeexe 6d54d5e52aecdd7abca8d6c5ac9fda1464595b96df9bd6b629604bc289cf6ffeVirustotal results 23.88% Heodo
2019-04-23S_V5.exeexe b73d0d387e795267c39d299027c57ab4e610b0e02d79c3b6aac0273e601eedc2Virustotal results 23.88% Heodo
2019-04-235G_8.exeexe b2bcb7fe83ffb8606ba25c652c5dfa2b2cf0dc694af39285546d44910b39f208Virustotal results 25.76% Heodo
2019-04-23Jh_ja.exeexe 7dcc05ba32a7a976675c7ffa234ab6d79d1de3208353db63821f571296784f64Virustotal results 47.14% Heodo
2019-04-232IH_Mp.exeexe 15cc5cc19e3fc4a096d4daf4a2eba362a7fc10b66223047584f910ba852ce666Virustotal results 43.28% Heodo
2019-04-23NlU_R.exeexe 7401c4eecd540d25a74dd082c684a7213ac1be666274d7ba96607f892421b95bn/a Heodo
2019-04-23zg_bMx.exeexe 787af8c65c4e745058b5e64a427c280fff9cee21ccca0563a0857faa70dab4beVirustotal results 43.28% Heodo
2019-04-23bY_Cv5.exeexe 94a9fc6b149a528e115e61fdcac954b27f0aa70df5a078d0de6b58e351a856e6Virustotal results 43.66% Heodo
2019-04-23r_H4C.exeexe b8abc7a915d025955ae020ecf1d68b3e7e9cbe337d5236fb56412e2f54d9b7d8n/a Heodo
2019-04-23W8E_kCv.exeexe de7291d05aa7dd4ef710022ce0913dcf438fb9c05597d72ba89887a84acab10en/a Heodo
2019-04-237ic_yMP.exeexe 7c26232667a88a5111926515d6a722362d46c3b04a552b18a1950ee1a8cb02f5Virustotal results 36.92% Heodo
2019-04-23K6d_B0.exeexe 9be8e489c2c33668a9ed18e99a39f40e68e7815380b8a012806bc93a8e6b27c2n/a Heodo
2019-04-23uf_X3y.exeexe 3f35934a965979ddc049255aaa589291cb1aae6d92fbf12ebd4e39b25ab68eccVirustotal results 32.35% Heodo
2019-04-23092_Je.exeexe 90aa2ea5ccbaab214a5c4521318d3f9093540d43e2b1204a2b5f9e86a1adee43n/a Heodo
2019-04-237gV_C.exeexe e8cf5ab84e10df84ca0ec5eb6a5046d0008933cf776b87391339bbcce02cbe8dn/a Heodo
2019-04-22n_4s.exeexe 6b721b19ab4c3b704518cb177a3fa098543d86660862410a0267925eb9f64cb4Virustotal results 32.39% Heodo
2019-04-22l9n_v.exeexe 8a671c4627b97c667b8f6daeab1fcf4ba8e9c1a214cab6b09c569540c056a288n/a Heodo