URLhaus Database

You are currently viewing the URLhaus database entry for http://windwardwake.com/YgRI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:20614
URL: http://windwardwake.com/YgRI/
URL Status:Offline
Host: windwardwake.com
Date added:2018-06-18 22:25:04 UTC
Last online:2019-12-18 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-18 22:31:45 UTC to abuse{at}digitalocean[dot]com)
Tags:emotet link epoch2 heodo link payload

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 4c7d08f1d6fac569c83fa87b42a3a727668da55317954637ce500d59e058fe03Virustotal results 0.00% 
2018-06-200989.exeexe c7c64507d9df7bc28d251132cb309b54b86e939d5e2e21894e0573e9a1ec9ddcn/a Heodo
2018-06-206454.exeexe e32e0086d5fe58bcc2a7357403359a2ef7b960e7d1ce7eee7d1bbf1d3b98d9a3Virustotal results 23.53% Heodo
2018-06-2089365.exeexe 9fbbcd37da800026d3dcd10d2e3cd622447ff0d91c65c6ddf4a232dee2b6f054Virustotal results 20.59% Heodo
2018-06-2029242.exeexe cc0208db49b171a19a6309301e78a0619bf3122887da1d28ea29ee0e84717026Virustotal results 19.40% Heodo
2018-06-2062494.exeexe 969e2c1803df2eda353feb8381687922d28d58bc2910feabc894842d4d9a388fVirustotal results 23.53% 
2018-06-206795.exeexe 7f198deac8ecf78fc1658728669c1523176a65d71e95605b28991b09a40a6259Virustotal results 19.70% Heodo
2018-06-205329.exeexe c65c398c73d376aec37efecef4dc3bb3d10180f8aaa75b08cff20fe72465dd91Virustotal results 20.90% Heodo
2018-06-2003676.exeexe 55a5dfecbc7aecb5e3f7759b246e23e36cbc1679fcdc2a66868147738501fdebVirustotal results 22.73% Heodo
2018-06-202377.exeexe ff3ece481e546e52c9533b71a66d79771ba723b16848db774bb2e2be2898385cVirustotal results 14.71% Heodo
2018-06-1909874.exeexe 03bbd70591730fdea53ee221cf0b4e6608062c266e5c5c745208c73edb9f755cVirustotal results 19.12% Heodo
2018-06-1902296.exeexe 506fa4b97cb81314aa929dee6349218e06e85fbc4f78469592e0a4b90eab17cdVirustotal results 22.06% Heodo
2018-06-192055.exeexe f6593f554c18488432c63b6a75f94cce4716b108bc98a6a5ed8e5f4d3d7cfc09Virustotal results 20.59% Heodo
2018-06-197978.exeexe 74d17cabbf16b414cf0be9344c37e073bf61c1aa6ec75d9f6dcda18852565555Virustotal results 17.65% Heodo
2018-06-1944141.exeexe 915b64fe237bde9c869863610f7c4ce1b1b88483cf022255c31fc9a91a76f970Virustotal results 17.65% Heodo
2018-06-1990466.exeexe b4ded18acaae89f67cf8b2dade26abec6ce61b39129c4d0c5edfb816d90d9b4cVirustotal results 20.90% Heodo
2018-06-1982067.exeexe 8f4a60c7f37831933a66622c0115190b969e7177de61becb83a6f27348662e21Virustotal results 14.93% 
2018-06-195351.exeexe d5dca9745f5c607f6e3697185fa9f76a290b12adbeae7717fb45e0543bc49c33Virustotal results 22.06% 
2018-06-192929.exeexe 5851de06355805666a1fa2f96b5aae45ddc3a78feabe386a62e81b17de071828Virustotal results 19.12% Heodo
2018-06-1952451.exeexe d0955bff94c8b4a8f068591a56e0f69faabc82a3cd056de543654b36d5a55e23Virustotal results 22.39% Heodo
2018-06-1835560.exeexe 0da38a1448c177a26653ee36b80ea357b1dc9353445ae32e17cae1ebff5905d3Virustotal results 20.59% Heodo
2018-06-187634.exeexe c040ac4054c4b454cbd442a1950e797859addf8f22e2bd8dc7e2e0451dbd8d95Virustotal results 25.00% Heodo