URLhaus Database

You are currently viewing the URLhaus database entry for http://tosetaban.com/en/lzm4t_j0x5h-611/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:194026
URL: http://tosetaban.com/en/lzm4t_j0x5h-611/
URL Status:Offline
Host: tosetaban.com
Date added:2019-05-10 12:19:09 UTC
Last online:2019-05-12 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-10 12:20:05 UTC to abuse{at}ovh[dot]net)
Takedown time:1 day, 20 hours, 25 minutes Poor (down since 2019-05-12 08:45:21 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-12ae_3.exeexe 1ef97f716d3276acbf45fd27e9f189714f6209a7f94df2d3750a05ade1a26cd6Virustotal results 26.76% Heodo
2019-05-11c_46.exeexe 0c4068d8afef6cbed8641586454b4ea3052d0825e579644f58ce64d3a4550886Virustotal results 26.39% Heodo
2019-05-118_845987.exeexe 52633981af075259928529e089741f226aefb674c179982d1c45276c27e3667eVirustotal results 28.17% Heodo
2019-05-103ti3z_892930.exeexe 2cc3cd285d85c714a7f82fc477dbc8b33c47a5d3bdc2a2d717256e4f082757eeVirustotal results 25.35% Heodo
2019-05-10cuumuaqwly_34375948.exeexe e28323ab72fe01bc966a60fada6b7b87527fee5380c36c03002d7813c6f96e48Virustotal results 25.00% Heodo
2019-05-1096my44nnv3_16898319.exeexe 704b6e4f208e1ae169162f345f954bbeecbbf0ec18185378336d8612d9eb1b04Virustotal results 31.43% Heodo
2019-05-10nh27s_334955.exeexe 43414e6536a731a248bd6041c09e033a9219eafccdb8dfa4c92360018a3505f8Virustotal results 60.87% Heodo