URLhaus Database

You are currently viewing the URLhaus database entry for http://4gstartup.com/wp-content/wotdrnPG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:201454
URL: http://4gstartup.com/wp-content/wotdrnPG/
URL Status:Offline
Host: 4gstartup.com
Date added:2019-05-24 14:05:10 UTC
Last online:2019-05-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-24 14:06:11 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:14 hours, 58 minutes Good (down since 2019-05-25 05:05:04 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-258opoplq1r_5837.exeexe 7b4951ce58280753d1d077e407e47b47e02011a30ae0f3374710feee17511cbdVirustotal results 26.76% Heodo
2019-05-25s6pfh_87.exeexe 6e9cf491bdfc0b73e1816cb8f38c925d09e8bd1fffd419e23c66ecac244d073dVirustotal results 25.00% 
2019-05-25roujawasnz_51325094.exeexe 1b9ccaf9f3b82e4ed792552f2c6e682ddd8dc25e31d4c6a3d823a54de6c3edecn/a Heodo
2019-05-25jv_147972.exeexe 5eae1bffdf49fe753ebf5671e594d766ecd2c4c707befcf3058db976c5440be1n/a Heodo
2019-05-25cg_87836.exeexe bc3f2781cb2c097d20241a23739d1c3fed4efa08f7ceb3366d4aee84588c23e1Virustotal results 36.62% Heodo
2019-05-248pbh1jn_3209343261.exeexe 45a11945efb1991d7216b2085fb82312ffaf0948915e6aff4fad652e0da5c9d1n/a Heodo
2019-05-24scc3i_34646.exeexe 9d88f95952ddd03b06edd3362a71d32a2135ec5fcea1c8d00034663f0d2d1ab6n/a Heodo
2019-05-24z1l_90023.exeexe fd61e3055f20fbc17c502fa9226bad4ccaf35d9f1cfa922e37ee226d6270e1abVirustotal results 38.03% Heodo
2019-05-24pqaffc_96493302.exeexe a39435557e8a51c980165002c3358aa5607b30f74b1cf618d8bd1487b4afcf7bVirustotal results 36.62% Heodo
2019-05-249_327404.exeexe d07be1d576c16deda5f48cc39011e909fd985688f724ac82b782124bfa470cadVirustotal results 37.50% Heodo
2019-05-245s_5951.exeexe c34d5ed95fe37918cdeb842208de6f5c78304719093645805cb95250b82b79a2Virustotal results 34.72% Heodo
2019-05-245hbni1oi7_2.exeexe 33b992100739b58865829a0c26c753637fc3bcc41f89656048941a623a12a4ccVirustotal results 30.56% Heodo
2019-05-243a3arq_265.exeexe ff7b1c89a8b6d464bc3f1f472a94641f4dcae99bdcf35dfa84c851116e917b07Virustotal results 28.77% 
2019-05-247p5a_5926.exeexe 612c10bc9196a1d593887b26d152a96faacc107e8fc3df5560a9ff1770bd4cefVirustotal results 29.58% Heodo
2019-05-24th4g_462665.exeexe 80e9e5da5225a3a878fe952d9ce123f1386cca79d3672211ae32063b2bdddaf6Virustotal results 25.71% Heodo
2019-05-24ng9norg8jg_18434.exeexe 37914a408026fb2fc3ede880f3b1babc821cc89558e14427bb0b3956d97594a1Virustotal results 29.17% Heodo
2019-05-24oo_5929.exeexe 91a6711cf2c3ef636a248ee03eca9d16f6b32c4e26335f9042a36974fc284821Virustotal results 30.99% Heodo
2019-05-2436_50048.exeexe 5cb83eb05c87a104a09e8acf859f00101e00c9ff5e00fb44c563d8c5f154e7e1n/a Heodo
2019-05-24q1zlmma9an_9303159946.exeexe 2d600efc22a5858b920f5bf51a74c17bd83f3f20d8ac8268b3a2f85d214dfb05Virustotal results 32.39% Heodo
2019-05-24b0i_146833.exeexe 98087d66f45bfd42bbc6aa2763d311d3fbcc6b42da1e6b24d6a9fe2ff005c80dVirustotal results 30.14% Heodo
2019-05-24rsepc0yxr_97794470.exeexe 10ef7829480e2c691b633f2546780fabe4733b6b32cb6878e7b3024d57ad6454Virustotal results 30.56% Heodo
2019-05-24fl_6.exeexe d889690b01c3f426cb06d036e7155d2157e34b81d99c755d99ebb152ad0dee67n/a Heodo
2019-05-24f_61.exeexe bdb20081a2b1994e3a3523fff8aa7ae75d9c5cf1009f5a0d6018a0b2ce57f167Virustotal results 33.33% Heodo
2019-05-244kmii2_43.exeexe 90ad956e082f45f7de26f3ff5bceee1a56bcff73dd9a489472e9290ecad0b320Virustotal results 61.43% Heodo