URLhaus Database

You are currently viewing the URLhaus database entry for http://www.enegix.com/pytosj2jd/v9s7ze3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:256372
URL: http://www.enegix.com/pytosj2jd/v9s7ze3/
URL Status:Offline
Host: www.enegix.com
Date added:2019-11-21 11:18:11 UTC
Last online:2019-11-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002114371 created on 2019-11-21 11:20:05 UTC)
Takedown time:6 hours, 33 minutes Good (down since 2019-11-21 17:53:52 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-21aoim7ucsw2l.exeexe 67d1ddaf25ed261fff138f47504e3f9c7e0ea40e28755bff3c19c0a61e5c8616n/a Heodo
2019-11-21zdrrrc2b.exeexe 6adec2e5e321997c94706829f6f25514ca2271ee16728b310b5c06c8dadae2dan/a Heodo
2019-11-21jf480mb6.exeexe f7a9d58d160583023bc0ca730e8e077cb35e1eb79ab004f64ab9ebe58631fcedn/a Heodo
2019-11-21yd6oc93dp7v.exeexe 7bd964cf9dbaffdea03a5304ee00363c0c503a372d1b669443968d83803e162fn/a 
2019-11-21uiawe6wr6xb170c.exeexe 8b6afddd7920aa4aa8945e2c8f516032fdc5bfc0d7a64fc7d7f95114712ebdfan/a Heodo
2019-11-21e0bjkf1z.exeexe 290d586f1c0930ddbb2c0a1318b25b9e5747bf01786cb9da02a87445ad82e567n/a Heodo