URLhaus Database

You are currently viewing the URLhaus database entry for https://avendtla.com/tcuv/pd27/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:203715
URL: https://avendtla.com/tcuv/pd27/
URL Status:Offline
Host: avendtla.com
Date added:2019-05-29 23:43:17 UTC
Last online:2019-05-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-05-29 23:44:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:9 hours, 32 minutes Good (down since 2019-05-30 09:16:14 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-309756u.exeexe 5853b6156dbcce59547308088a3e74982f7adf38bf00f9d370d5de44183d536aVirustotal results 25.35% Heodo
2019-05-30oogwsuom2fwuup.exeexe e3b76292b9cc50ec575ef4372763535273fa8854f03b4bf649f511def3111562Virustotal results 28.57% 
2019-05-303rn404l8um2yjb.exeexe 0908229db381ac41a922f8260e6cbc8a6e4254f6d746879623da3cd9dcf61b9eVirustotal results 28.17% 
2019-05-30dpxl7ud52vk.exeexe 7b2acaad74f37fb9cb885056a9a653c58f191eeff96f004cd8b1f7588cc35847Virustotal results 25.00% 
2019-05-303d6xem.exeexe b3017fd595ddbbf77285db18a650381bdea315945725272500422f96a73c1e29Virustotal results 23.29% Heodo
2019-05-30p3d08s3eml.exeexe e8739cbb87b2de2ff0fc396f1bff6b4bf30d9e529057bfccf75d72e0ae57ae59Virustotal results 25.35% Heodo
2019-05-308cxcdldvj.exeexe a32976c628063b87dbd2187b1527c6ff66875c0ba372c01155a7851d76ee01c6Virustotal results 26.39% 
2019-05-309wznwwtlkhlxll.exeexe 84814627daf5dc0e87c67a5d05ef49c7132f45e1f47ef1964409101daf266511Virustotal results 27.14% 
2019-05-3074jxg48p9.exeexe 48047389b0c8da1b03a2cbdeefbe45dcd551aecd9067bde536118ca8ac3b2edcn/a Heodo
2019-05-29p2ee97ap7up1bj.exeexe b8c2109f68133a0582d5e29d09f1a38562b535eb9bd501d11793e4ab7218ca40Virustotal results 21.13% Heodo
2019-05-29wmjzs78zsmq.exeexe 41431cbbd115c2cc1c4afffd26f5ad17d76a7c6f7fce963519c1fa388bae0e6aVirustotal results 21.13%