URLhaus Database

You are currently viewing the URLhaus database entry for http://fafhoafouehfuh.su/11.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:196689
URL: http://fafhoafouehfuh.su/11.exe
URL Status:Offline
Host: fafhoafouehfuh.su
Date added:2019-05-15 12:11:12 UTC
Last online:2020-05-16 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-05-15 12:12:03 UTC to abuse{at}freebulgaria[dot]im)
Takedown time:1 year, 0 month, 6 days, 12 hours, 56 minutes Bad (down since 2020-05-16 01:08:43 UTC)
Tags:CoinMiner CoinMiner.XMRig emotet link exe GandCrab link heodo link phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-20n/aexe 68657be04f5b550fec4671437e5dc5849408eada96f5ff44cb0972b0e28ca5ben/aPhorpiex
2020-04-08n/aexe f8a3b64aa3c1c639a5ce1b100de860d4f97703879df0d01ce0118ae97c1b7423n/aCoinMiner.XMRig
2020-04-05n/aexe a8f46fedf70cc67b71c9e147d30b72d6ca8b9708ec73e45e48b83bb97a383a65n/a 
2020-03-20n/aexe 11b00a800ef9e28b93329362c4923340080370bd506627273207ca1a422a4534Virustotal results 32.88% Phorpiex
2020-03-17n/aexe 993d2f33be65ced84cdcaff1e57616a80f708ecfacb6f7b12c94aa65e121f080Virustotal results 35.21% Phorpiex
2020-03-14n/aexe 03618500f13e022c459a4bb603f40a464b5c520907a0634d442fb9c4f8f27d29n/a Phorpiex
2020-03-12n/aexe 260623d46d2b96d2158293bd8eb21611a4d5dbbbd7996abcff2fa5d17d84a0acVirustotal results 34.25% 
2020-03-11n/aexe 0fdd21beb009e9675f955733c80e8053b5dafbb12d22b9cb761af3df82be6505Virustotal results 26.39% Phorpiex
2020-03-11n/aexe 9d378340ae4e0da80a590927f139f70a875b3809592139024bf27e4c70997f9fn/a 
2020-03-10n/aexe a9e8cc04eb20306734cbb0aaed90746f2e87260a1d66f20413efdf1c331fe0b0n/a 
2020-03-10n/aexe e115c62d6bd273a988c07570b40cd9caed1873b8bc85384797debb9182a113fdn/a CoinMiner
2020-03-09n/aexe 468340a7d422c3525d4bb9c274511d77ce715f86f42eb8c790f5cc59bda6c32aVirustotal results 27.40% 
2020-03-06n/aexe 8a3b9a9dc3f14dce7dff9280df58eeb183b4f3b8c57289d05212ce22e25d1c16Virustotal results 20.55% Phorpiex
2020-03-04n/aexe 40a6fb569e0abd218106b96ea9f7f6e74e094937c63ed4fcd44bdd754542228aVirustotal results 20.55% Phorpiex
2020-03-03n/aexe 1565d1de4d537a94e30ccfa2fcd87fcd56245fb03f72ff680ded7c1d1850ff68Virustotal results 33.33% Phorpiex
2020-03-03n/aexe 2d78656550bb256779b9cadbf5970b5b9b097e600bb6d00bd91775c1eef84609Virustotal results 58.33% Phorpiex
2020-02-12n/aexe bfcf5fc1fcacbddc064955b2fe662a88f27dde3056d116dfc7857c9261c27d1bn/a 
2019-09-02n/aexe d12100599ef8bf6d65b49159a00713e7e147d19d387af087e7313fa3a5ef473bVirustotal results 72.06% 
2019-08-14n/aexe b2ab7405186aa88a72c21e7ef3a5fa5e9f0ca25aadfb49c80e8b09ea507bd054Virustotal results 35.38% Phorpiex
2019-08-06n/aexe d0fcb364a1d37c93740edcb88695de72de8b53fcf29c6bb0fcbc792897fd9b8bVirustotal results 24.24% Heodo
2019-08-01n/aexe 77689e7752470501d26cf8a5e2eb9b4e1ac372b27b2151268e0acf024e355f99Virustotal results 16.42% 
2019-07-27n/aexe 1ab8feefd67f3706a42f996a3291d24a7ab2c5eb67d98236eb73995d587576adVirustotal results 17.65% CoinMiner
2019-07-25n/aexe 29c5bee50ae4ae71dee17438c7833ce25eac1a7dad491703eec74cf266b0e889n/a CoinMiner
2019-07-23n/aexe db9e9ebd3bde83b601be37c975f9a90edb75bd09dff87548c4bc1157eaf73fe6Virustotal results 27.14% CoinMiner
2019-07-18n/aexe 0c77b260ee3fdd2754cd4f289efce709519aad34fa3cb84663655a6240e45973n/a Heodo
2019-07-18n/aexe cfa7edc52cb8289ea0822520adf2c116c879c522af81a8aea35e9421a9019535n/a 
2019-07-17n/aexe 64d187bed40d023e14d41b1a80d528f5c12dcf743fcb4de91530567d3244e09eVirustotal results 18.18% 
2019-07-12n/aexe 6379c818071dbb2ef35c6f56c1bcee95da8791a5f24f4f74cd6c5deb788384e3Virustotal results 54.93% 
2019-07-09n/aexe 9dbbb31e9df0c42d83a0fa7b610a9438dc3d727d8dd7eaa81418df25f87d5981n/a 
2019-07-07n/aexe 9e38c7f093d4f02631406ca00ed549386e794bf7bc0c53e6147b1cbaf10c8a69n/a 
2019-07-04n/aexe 48393fed57d7c4309373e400080449afa794f665f1a573ab26cfb316de4cef80n/a 
2019-07-02n/aexe b1650c6085710bd89fdec14ce9a1a5f52d7199ab98671d994181b1e7116a0a86n/a 
2019-07-01n/aexe 7f9af5447e0da4702f9fefab0bb095b1323813c657c7387e74dcc0774f691349n/a 
2019-06-29n/aexe 7cb48b10cceccfbbbfb67677ddc9df820ee8c6d45a371dcf75edfd2fac8bf078Virustotal results 25.71% 
2019-06-27n/aexe fd6f317840d4aff0a173ec79b2c425461a4ecd46b33ce7b8f83efd8df6f8c9b2n/a 
2019-06-25n/aexe d29b5cfe743635c3ca941df6086f2c6440d376742e7984f27c066d59133a0b40n/a 
2019-06-24n/aexe a7ca204632f7c62e75b02978c62be386b47d4d0741f9bd7d826986cef7ca4304n/a 
2019-06-24n/aexe 7ef44ba16d0b062fa006d6da758affa17fbbeec52d3923324c1501d9dcee3a71n/a 
2019-06-23n/aexe c6c6735b4111fbded7e1904b892104bf022e3425af374936d9d3a8b56b4a27b7n/a CoinMiner
2019-06-21n/aexe 2253bec8888c6c8fa3227dd6f33206e412309f0787ee67deefa63c50e99b4645Virustotal results 22.86% CoinMiner
2019-06-19n/aexe 94869576b92022ee8e17fd3d6663fdae331870eb9d83854787626b32f3ad84f8n/a CoinMiner
2019-06-18n/aexe fa9020c32b1c1b810b6c261e77863411bc64e70aed6d2a3bbbb82ebdcbaf8740n/a 
2019-06-15n/aexe 24a341780548aa0e17616e48dd1286ef91bfd9efc928820b8aff7c14c85a0189Virustotal results 21.13% 
2019-06-12n/aexe f06bc76647c37e85b60aec384eba21a56a3dc2ddb0b962536b05f1b827fee8b1n/a 
2019-06-10n/aexe cdcca64a29f0bcd58c8a806a0bde74c82f51989e15a01f191fc4f8c31cd640a9n/a CoinMiner
2019-06-08n/aexe 6606987e6513c7738bcdfaa3d8422ef8a0385aa229ebea26de11e27074f6882en/a 
2019-06-05n/aexe ac0ea171c290812a7cd4cb774a12fb48b58e0e51d961404c069cca78af33d99cVirustotal results 27.78% 
2019-06-03n/aexe a8a87269b327752b7c38e1102df56a4fbb06721d753783b59a58c31882b6e153n/a 
2019-06-02n/aexe 7b0aab33ef164f9ac355102aca78710761abafedec4463e07312fc6d67668082n/a 
2019-06-01n/aexe 3c003520a83ed5b79d6aa53c0df087379137b4ebe26b2b501b27b014ccadec37Virustotal results 20.83% Heodo
2019-05-31n/aexe 021a38e1421d50fe09927ca136fd3282e11f30a48029ae253ed3ef0a6b62c23cVirustotal results 22.22% 
2019-05-29n/aexe 8eabca3a0e42d3502043af28f360c99317310397a3e8c4b5cddc11a2e75ec5bcVirustotal results 58.82% 
2019-05-17n/aexe c16b53acd39eec526698c8e4e90956880b1cdd30554d08086fe94b833ee3a5b3n/a Ransomware.GandCrab
2019-05-15n/aexe 2aae2375a8cf31575ea9a80bdeddc9ec97586e156e4d0d466d42ffec800ec267Virustotal results 34.72% Ransomware.GandCrab