URLhaus Database

You are currently viewing the URLhaus database entry for http://ravefoto.de/wpp-app/hlsgofCiuB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:18534
URL: http://ravefoto.de/wpp-app/hlsgofCiuB/
URL Status:Offline
Host: ravefoto.de
Date added:2018-06-13 13:55:05 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-13 13:55:37 UTC to abuse{at}oneandone[dot]net)
Tags:emotet link epoch2 heodo link payload

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-1487677121.exeexe 88a0c5ff1df41f7f59ff77e23b7bb277085ffe0ab3ef18392b5a1516c29eedf8n/a Heodo
2018-06-1357777139.exeexe 9fc7de6e125b8c238a07c470d26fc833db6c05cc0aaae6558cbe716edf0a1190Virustotal results 10.29% Heodo
2018-06-133268421523.exeexe ab34e236f9efe6eba1de71f288a659bfa22a7544daf46082b6757b668ec1fdccVirustotal results 20.59% Heodo
2018-06-13011826524.exeexe a662322837493e4c3963b1d7749d320a9d5d0fb276f7baa404c4886d109cd862Virustotal results 23.53% Heodo
2018-06-1370062166.exeexe 60d95c9c7ebf04e2004264eb1198bcf16d4545830e38999c8ee161a457029ca1Virustotal results 26.47% Heodo
2018-06-1373601839084.exeexe 68ae7341e5e4453cee075fac2f459be5ef8d005fb01b19d7d287d88e56101dc1Virustotal results 23.53% Heodo
2018-06-13981676063.exeexe c19076137a88c591febfadcf1fac8559d1fb45b99ad8f7c200029a99139fe524Virustotal results 23.88% Heodo
2018-06-1312895658891.exeexe 819258193db9232435ff8c3b5d982e4e8044daccb0c426e30ef13b1155f875d2n/a Heodo
2018-06-13563358791560.exeexe 3a2ce5a22799bd30c94e23bcb38a41a72f871f5e3d820a90ae6048039f2aa658Virustotal results 25.00% Heodo
2018-06-1385059931388.exeexe e2dfc67fdda9334c5ffca94fa258bf8ccc41e77f464a6ca4252c4b3ee49a37c4Virustotal results 23.53% Heodo