URLhaus Database

You are currently viewing the URLhaus database entry for https://www.pfgrup.com/wp-admin/so0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:257905
URL: https://www.pfgrup.com/wp-admin/so0/
URL Status:Offline
Host: www.pfgrup.com
Date added:2019-11-25 13:35:16 UTC
Last online:2019-11-26 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-25 13:36:03 UTC to abuse{at}megatrhost[dot]com)
Takedown time:1 day, 2 hours, 16 minutes Poor (down since 2019-11-26 15:52:19 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-26ihtmFke7.exeexe 3ca24b93494bb37287fe07f4a6fd2301a2196f2ca95fcd1ee873d04db8c6f0bdVirustotal results 22.06% Heodo
2019-11-26dw5KwD.exeexe 44ec2da7b6e45dd57794c782932788c5f88b51f080aba385d7906a675799f3ccn/a Heodo
2019-11-26eFMhG.exeexe 4e526bca56797685b683100e9163ea59804118ed876c057c29dfb5fabba4b267n/a Heodo
2019-11-26UHg2REByf1KNeR3.exeexe 27d39ef5e11b297900011bddf56a27369c28e26a433f417dd2d83c63a4a024b7n/a Heodo
2019-11-26Fx4CISaTKU.exeexe b7b02be11906120cee18404ac0e474f05406b868a19546069fd935c9164a233an/a Heodo
2019-11-26piPS9q5.exeexe 3b082a3a4e9f0dc7f01adb4096afecb00c7477efc638af7321c98591c89eed0en/a Heodo
2019-11-26IlkkcRpXsLfDKyX.exeexe 2bd362b1b1d40dca063a8724598af78d6e5483a99519e48ba7a3b39391acd969Virustotal results 29.41% 
2019-11-26rjRiYxbzPz721tHRO.exeexe 436c9af8ab6785139a8df7dfc3678a3d6045f6a8fda6707d1ba6f794c4f970c7Virustotal results 22.86% 
2019-11-262LBlIJ6GuLT6D.exeexe 71649a7ded9e9d2a692b4a362f96b0beca23c1ab7c4b68948dd8874d69994aa6n/a 
2019-11-26VVKtszzHpfqp.exeexe 903a8147323903519855c090a96ab8a01998fe93d52bbff743b5b1ebd96b5380Virustotal results 21.74% 
2019-11-25dyYtIfp8p8wSHEF1.exeexe 7013664f5297df77c2f0af1b9c9feb309eb406370b8278658cca7fdd43a3912en/a Heodo
2019-11-25xPMLU0JDheQ1W1.exeexe 9d5d19879955b1f8040f5dc5e3f4480bf454368dd8e98099a720be2948b53902n/a Heodo
2019-11-25rFSlY14tBHHaXmCgHULP.exeexe ae942ac0df226afd76361d0e76fcc02b5c9ea54bfdbe42100ecb6f47968d2b2dVirustotal results 22.86% Heodo
2019-11-25mfdPZSLZ.exeexe dfeb8fa5a5eff0a2e48db2e62088ebc75624bd83fef7efb15ccb4bc7ac02bbc9n/a Heodo
2019-11-25GXtcJY.exeexe 25ca902b6f9552b80c0457962d01490cb362c16ebc2b1933939d34b1ae2c95adn/a Heodo
2019-11-251MajwuIIaR3uyKp.exeexe 4f99d88505910dbb6af6f4ecfcd810cf4dae7340a1356b53c139cc63f531c683n/a Heodo
2019-11-25ieS.exeexe 5d08288f442f37af91f5babb04a5a53053453cefeb9e8c7994a55f7e1083a73cVirustotal results 17.14% Heodo
2019-11-250AwVnLC59T7neQG3ydrQ.exeexe f56b50e1d29884c94014e3b6163fbef377885bc070fed9409369190ff295e44fVirustotal results 14.71% Heodo
2019-11-25rb0V.exeexe 19b8924456f7e87a5063bfd2c1afb41de3cdbf1ae80c7e83233f0ae1e1ed4173n/a Heodo