URLhaus Database

You are currently viewing the URLhaus database entry for http://oilmotor.com.ua/9jrQva/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:19105
URL: http://oilmotor.com.ua/9jrQva/
URL Status:Offline
Host: oilmotor.com.ua
Date added:2018-06-14 14:28:05 UTC
Last online:2019-12-19 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-14 14:30:13 UTC to abuse{at}ukraine[dot]com[dot]ua)
Tags:emotet link epoch2 heodo link payload

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 6c625bb809925a74fc67be84df2fcb65f8972c6341fc01c3c4c51e7083769053n/a 
2018-06-15406038675697.exeexe f3d05003409e7aef689d2a64aebfc4c172dc2e548e5524634dba9c03c11d313dVirustotal results 23.88% Heodo
2018-06-1491651679034.exeexe d83fdf8685269e9816ade956f3d8eb3cd6cf1a07892dc02a66019f55b82b92eaVirustotal results 28.36% 
2018-06-147637499819.exeexe d9d268ea693b145725fd4f96ec702d2e07a5c792c4cfd2d92d9a065261ebe16eVirustotal results 17.91% Heodo
2018-06-14686013665178.exeexe 2127a2f7c3214224f299f31674e720c56df65e7670dd09f7d27730845bd83279Virustotal results 20.59% Heodo
2018-06-14357916076745.exeexe 365e610d4f1b9ed29bf1fae517510f155f61b23ae06fb5f002752e75b2434651Virustotal results 16.42% Heodo