URLhaus Database

You are currently viewing the URLhaus database entry for https://navinfamilywines.com/alloldfiles.zip/zegkb671/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:203053
URL: https://navinfamilywines.com/alloldfiles.zip/zegkb671/
URL Status:Offline
Host: navinfamilywines.com
Date added:2019-05-28 15:15:06 UTC
Last online:2020-02-28 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-28 15:16:12 UTC to admin{at}internetnamesforbusiness[dot]com)
Takedown time:9 months, 6 days, 6 hours, 4 minutes Bad (down since 2020-02-28 21:21:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-30kyrlf.exeexe 7be0e9c07bcd72defb5ef68ff68f9874cfb56173e4163a306f5ff31de85cd3d4Virustotal results 26.39% Heodo
2019-05-30bdqmq.exeexe f57abb64deacd21d35879645282cfd1269c23e18df437216dbfa194df9ef60f0Virustotal results 26.39% 
2019-05-30anbwqeph7.exeexe 56cb8cb05675d93bba4b607aab0f2d7024e4aea40178cfb07e99a6c4e5e204b0Virustotal results 27.40% Heodo
2019-05-30szanov4e.exeexe 6c44fc066a5bb7ecb21e95df9883b9cdd91a0c66e6ecfca29bae4f4e88a5d18dVirustotal results 26.76% Heodo
2019-05-30vhfslvbj04e.exeexe f8e3e8788f0da3076df77ffcce09e4055f05fdb6d5ecdf8767b616b08b489cb8Virustotal results 28.17% Heodo
2019-05-30ypjbewz4syoicjk.exeexe 925ed9de954e0d254b5710ceea84197ea873f1988f3b547eb2eb9f6acd5ba7e4Virustotal results 25.35% Heodo
2019-05-30z0p9qpngnea5vt.exeexe a154e76a0d335465176bde498e39dce28ed50db294a9998d721033d8e69b3158Virustotal results 27.14% Heodo
2019-05-30mywo1zmbfmiieh.exeexe a6d08809f108ee4cf05fcd86d159dcce8602d2ece7e7b563f30010bfbc9028aaVirustotal results 26.39% 
2019-05-30j3bap35ncm817q.exeexe a01c858bd87a84311ed78aaed3c6e1e66896f46ec6cc1d502620040e81f1e879Virustotal results 26.39% 
2019-05-30ubufz0x.exeexe cf1790df9100561e67099774ac5a258e43cebeea108d4a1a185a36e5526f636cVirustotal results 24.29% Heodo
2019-05-30625g848thk532w2.exeexe de79dbe3f4bd7a5c6ebe3c007b8d4ffbbf4c19fc7ad30127e71ec0a7855f21dan/a Heodo
2019-05-30lxvrpnaxjaz.exeexe 824da9c53ada185014e3d2e71ad72d3536880a2abff82bd95e1ffc3ecd04f33dVirustotal results 21.43% Heodo
2019-05-30s40stx.exeexe b3017fd595ddbbf77285db18a650381bdea315945725272500422f96a73c1e29Virustotal results 23.29% Heodo
2019-05-30wh89fcop4b3h.exeexe 1c6bcb5ea3c05fbab6d0c382521e175854365409f4b802a166e3235dbac09493Virustotal results 25.00% Heodo
2019-05-3034rwsey.exeexe 9ae6cce86711c331387f31950a2d5110a577f50017561d6f2eab615f0e860d43Virustotal results 27.78% Heodo
2019-05-30hzh156vj09.exeexe 84814627daf5dc0e87c67a5d05ef49c7132f45e1f47ef1964409101daf266511Virustotal results 27.14% 
2019-05-30e53wtgy3k6ba.exeexe 65e673d348a6ca83af819ad2aa97960411132ae5de10d4e9342d5457005730bdVirustotal results 21.13% Heodo
2019-05-29pdvim697j.exeexe b8c2109f68133a0582d5e29d09f1a38562b535eb9bd501d11793e4ab7218ca40Virustotal results 21.13% Heodo
2019-05-29igo0d.exeexe 00054a00efc35255e8df5b24d81e102357b951a222bf2af1fd5662e0dc6a134dVirustotal results 20.83% Heodo
2019-05-29pmvlazuhxn3rs.exeexe 6e535868daa5f8ad68491ff61741fce17313814c029863eb9aa5b36290b7e721Virustotal results 21.92% 
2019-05-2955cds6xlmmky7.exeexe 1c329a3284737d400b6d2ae5f926ba51640cf8c60e5ca888d8352ada5d77aad1Virustotal results 29.85% 
2019-05-29hs538awz.exeexe 21b1e403c056644edcd892ce575070526c08e659a7bdb6052886b0704e07317aVirustotal results 22.54% Heodo
2019-05-292leur.exeexe cf0b09c156fe12dfa38e308f05b504048616e44415b10b3c28521dcc140029fbVirustotal results 21.43% Heodo
2019-05-29y16w3400vnn4o.exeexe b0448288f87c262978d137fb52e2b3f77954510fecf0c205f3cbe537f352b4a3Virustotal results 21.13% Heodo
2019-05-299lprjjb1.exeexe 25c9e913e8a32313f6df9c5eb4160d05be789383198fb31b7c30c5dd9d7a9021Virustotal results 21.74% Heodo
2019-05-29pka91i.exeexe 9e46fb8cc4c291f7364a68d16089dbc5fbbd2b78ea34b035398ca33cf041ab51Virustotal results 25.35% Heodo
2019-05-29e4z0gtxiukvpn.exeexe f190e434acb1e629d305d8333fccb24e2067f8edee52fa315eff7e0d2b58eccaVirustotal results 30.14% Heodo
2019-05-290seqornhfg755a3.exeexe 8a9e04379bcdf06ceb647e7ff76b42646d781742af0abff320c2679bb5c8c2f3Virustotal results 23.61% 
2019-05-28eds50ked09i48z.exeexe a4127b2ffb99d871dc3c0b5aecccf4a508f969e1efbefc4fbd23d2bd1519ffd5Virustotal results 27.78% Heodo
2019-05-28pl6aiy23.exeexe b55138efe9e2fed5d2a26240e15dda4222b29085d6676e26a04d9fbdfa6ac2f2Virustotal results 36.11%