URLhaus Database

You are currently viewing the URLhaus database entry for http://kulalusramag.net/calendar/lznsbh5579/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:193003
URL: http://kulalusramag.net/calendar/lznsbh5579/
URL Status:Offline
Host: kulalusramag.net
Date added:2019-05-08 17:47:39 UTC
Last online:2019-05-10 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU001373591 created on 2019-05-08 17:48:04 UTC)
Takedown time:1 day, 6 hours, 49 minutes Poor (down since 2019-05-10 00:37:28 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-1009q5011h.exeexe 16d444ef20cedb8a31b7b4731bd23e687055185b489d3c46398736466869eaa3Virustotal results 21.43% Heodo
2019-05-09ddqlpx6nskpn.exeexe db68ce6c26b0f1dead656ca23d8b3596755bc0229d55dc9a46e2a94879fd6913Virustotal results 28.17% Heodo
2019-05-0925sr2y3ewuq1ni.exeexe 3e66c17ed85f736d462323f0042cf3faab1940d89f4d42c08f1b5fe1110f1e31Virustotal results 21.13% Heodo
2019-05-09rj5poq3o0szpe.exeexe f1501a38109f806e0d0fb55361eef79e0074b4c6c636102bfd37988f8c0cf7b1Virustotal results 20.83% Heodo
2019-05-09askyjtqbq.exeexe ca221e91bfd2d2e7e93196c11ff4db0713f1e41675cc1f1b13b7b742c94612d0Virustotal results 20.00% Heodo
2019-05-09shxkr.exeexe 38fc7394bbb415b43673166d69206333c150e23f6b9fa92ca9da48f26d7d6b9eVirustotal results 34.72% Heodo
2019-05-09569n99yjrb0zntn.exeexe 3dcfdf41f8a42f11201c56a44873b9c1b8fcb676b48d69ea0178ea66fc9cd7faVirustotal results 30.56% 
2019-05-0911d1rjl88s6i3.exeexe df8c30d18c869eb0686c92da421db02af673bd326b83b118745f61bb8ab39e33Virustotal results 30.56% Heodo
2019-05-098uhiaewkv.exeexe 2db51ad624239421ceffb9dd45c898ed1f64f0316e6ddd43e276c7c1ba7f97a2Virustotal results 26.15% 
2019-05-09pie0a.exeexe bf6f9f8f38399302917fd8d4b2db61ac34fc61bb72c049506c602ac3542db636Virustotal results 27.78% Heodo
2019-05-09oug77.exeexe dc1f72dfdc516379ba2d1cee97f30d5625b11ac8d506515418f21516e369165fVirustotal results 27.94% Heodo
2019-05-09xgdnmni.exeexe 4344b71e75aa89b2eb269c20f97a7bf91a527a3b2a3d7fe6f5aea0164b36a454Virustotal results 27.78% Heodo
2019-05-09nllxau2.exeexe 5a95643eff566e655c27cb7f8e37d4e4c3608fff711a4987033b2fe25bca5f8fn/a Heodo
2019-05-09t06qzl.exeexe 7ed0f2dd345574c60835da6dd0312823fc3e86851006211f6a9203614ee93907n/a Heodo
2019-05-095g1wkbwilg7.exeexe f886202f15a93ff1bd3522be14dd3143c4f7443cc700c7840fe8667e8abf4656Virustotal results 23.19% Heodo
2019-05-092oieqduh89p1.exeexe f47aa9597beaef527cd5ba9d00a9dcb9fb0d2633ab46fd345136469772c9c6d0Virustotal results 25.00% Heodo
2019-05-09zc9bo.exeexe c9c9bc27f596eb25d234491aeb394d85bbba1a640bcf72f39e4b3c373fbe8eb9n/a Heodo
2019-05-09yy3gi11.exeexe a05c2e598f4a32c8a38699ed5c4be8921c1664841365a0f2e1cb580cb124ec00Virustotal results 20.00% Heodo
2019-05-09bcni1kpowf.exeexe 3478eb7d70c27498d0c4bd842f41313c3223fcb9a572a6b57460fb556cf4a866Virustotal results 21.92% Heodo
2019-05-08d9rh0vkg9jhxgla.exeexe af50c77e63620eccb3be78fce0ed3de6bf9aa6812fbd7e503e6488abddf31a4bn/a Heodo
2019-05-08ta97s8.exeexe 150b5ee89d07ba59cb43ebd1bddab22244667009b7bc78d5e4ae6b37aecb373cVirustotal results 20.55% Heodo
2019-05-08sjs4od4iazwimlj.exeexe 1d6458fe846c15db8207de992b6d921735c94ca7f690935df33dac708c86098aVirustotal results 19.72% Heodo
2019-05-08rotd4pqe1.exeexe 172591f8375a492a1f99412e8b103300efed99734db0781f6abe69105be97636Virustotal results 21.13% Heodo
2019-05-08owjjqr.exeexe bbc8c3c31884afca6d606d0641864d69459d9f609d92bcaddaa039ac17dc150en/a Heodo