URLhaus Database

You are currently viewing the URLhaus database entry for https://www.offmaxindia.com/wp-includes/b161/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:234865
URL: https://www.offmaxindia.com/wp-includes/b161/
URL Status:Offline
Host: www.offmaxindia.com
Date added:2019-09-23 22:29:04 UTC
Last online:2019-12-06 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU001962328 created on 2019-09-23 22:30:05 UTC)
Takedown time:2 months, 13 days, 6 hours, 54 minutes Bad (down since 2019-12-06 05:24:55 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 7741afc05138559deb31500c259df69c4feb4adba6582175f71059642b016e87n/a 
2019-09-257e6s2.exeexe a3ddd4b68151f13a5badd987e53bb4520f8fcab1bab46b88efdcb475b5acf3e5Virustotal results 11.76% Heodo
2019-09-25zytlx7h.exeexe 7b19d210d01ac6cccebd6e472f71f775c8f2daf2418017d4cbe96fc70529c0beVirustotal results 11.43% Heodo
2019-09-24rdiv34f66frt.exeexe 3e269b0ba5c550cd0636355f2b8da977dac2dc4ad42bcf8b917322006ccf4745Virustotal results 8.70% Heodo
2019-09-24uvkv7rppww8yyc4.exeexe 10e0034ee35b6a21baeb46ae2d54422dbb2d6a11556fe43f405303463dc7548dVirustotal results 24.29% Heodo
2019-09-24stb04e.exeexe a22732be1da7ae878bdc01f7e2431030c616a071a56d5324f1771ef942a57e82Virustotal results 12.68% Heodo
2019-09-243zrdqzlo9.exeexe 0577bbd2dc8ac482ab9d2d0b93ffaa319d9cf8d45349aa4400cea1ddd07344b7Virustotal results 7.25% Heodo
2019-09-24qcwj08v.exeexe 39662b355dfc2952a149eefd54d966afcd4527134a639d0bac8c748571e990b9Virustotal results 5.71% Heodo
2019-09-23f9mb9bqeehvfoyd.exeexe 139f9955e4a2c78c885194e85c16fa12c1ffcb200dc9a3627a0593b4de2f9813Virustotal results 10.14% Heodo