URLhaus Database

You are currently viewing the URLhaus database entry for https://hhe.eiwaggff.com/files/pe/ytaa1115.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2400274
URL: https://hhe.eiwaggff.com/files/pe/ytaa1115.exe
URL Status:Offline
Host: hhe.eiwaggff.com
Date added:2022-11-04 06:25:14 UTC
Last online:2022-11-26 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: jstrosch
Abuse complaint sent (?): Yes (2022-11-21 10:31:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 4 days, 22 hours, 50 minutes Bad (down since 2022-12-09 05:17:28 UTC)
Tags:exe fabookie

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-03n/aexe 2d3b23a32b2914278657009d60352213798685ada999d5fc1f76bf8ec219e83en/a 
2022-11-24n/aexe 32e8a18cad6c3e8900824fc1d65f23031a38f7e54c7e6dd2c927c67200d5beecn/a 
2022-11-22n/aexe b9cf0803f96192ddedb108f44970a554985d5bad0577b297da4c7ddae730eff7n/aFabookie
2022-11-20n/aexe 9115f862749d773cd737fbdaa4c3e98b4d5458527c54438c49566146730ee229n/aFabookie
2022-11-18n/aexe 1b67efa690ee66657a7d2a1e7438bdf7e74e64f4fdfa85e4aefceed1e0e1040dn/a 
2022-11-15n/aexe a43ba866355013dd2afd3c89ad4cd9427b7c209cae3c09c157843688cdf81e18Virustotal results 28.99%Fabookie
2022-11-12n/aexe 2853bcb79fe32b2abcf98713e3bbffd82d881149bbb1a3ee8c97a254dabb129bn/aFabookie
2022-11-09n/aexe cd9e01041452a569bc7886a2b669ef9387e6d6a8f56b124c0c2e10f3525cb51cn/aFabookie
2022-11-04n/aexe 72a38b7b1c14bb89928a4fcac764d081d0b9df697d101045140aa81be828a385Virustotal results 7.04% 
2022-11-04n/aexe d3b87ec103a87ec23a322592a754d114500a0863d7536dc4b105d2671ac453beVirustotal results 30.56%