URLhaus Database

You are currently viewing the URLhaus database entry for http://fafhoafouehfuh.su/22.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:196690
URL: http://fafhoafouehfuh.su/22.exe
URL Status:Offline
Host: fafhoafouehfuh.su
Date added:2019-05-15 12:11:23 UTC
Last online:2019-07-25 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-05-15 12:12:03 UTC to abuse{at}freebulgaria[dot]im)
Takedown time:2 months, 11 days, 11 hours, 37 minutes Bad (down since 2019-07-25 23:49:04 UTC)
Tags:CoinMiner emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-07-23n/aexe db9e9ebd3bde83b601be37c975f9a90edb75bd09dff87548c4bc1157eaf73fe6Virustotal results 27.14% CoinMiner
2019-07-18n/aexe 0c77b260ee3fdd2754cd4f289efce709519aad34fa3cb84663655a6240e45973n/a Heodo
2019-07-18n/aexe cfa7edc52cb8289ea0822520adf2c116c879c522af81a8aea35e9421a9019535n/a 
2019-07-17n/aexe 64d187bed40d023e14d41b1a80d528f5c12dcf743fcb4de91530567d3244e09eVirustotal results 18.18% 
2019-06-05n/aexe 1d8fd7ebe1a9ef61695e0699220c3477b0f947ce4a27a01dccb3b2ebd959ee5eVirustotal results 34.25% 
2019-05-17n/aexe 290d5d4bee5db0a583df35acc29ea88054006ac38c82dffc23168c3ce1b5b32bn/a 
2019-05-17n/aexe 6c76aab4a2ddd1d9d0879f714e27732049c3cd93b55a718b6180c49beb8889c3n/a Dyre
2019-05-15n/aexe 821a90b8df936ee05db98967e4591511978d723bae1a834ad8bb0177fd324529n/a 
2019-05-15n/aexe 7e0b43b7f4fdf7e1bfb01caa8ab9245c5ca0b80a2744a8e780354693ac28043fVirustotal results 52.78%