URLhaus Database

You are currently viewing the URLhaus database entry for https://www.bastem.xyz/cgi-bin/MLLB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:258075
URL: https://www.bastem.xyz/cgi-bin/MLLB/
URL Status:Offline
Host: www.bastem.xyz
Date added:2019-11-25 20:53:05 UTC
Last online:2019-11-26 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: lazyactivist192
Abuse complaint sent (?): Yes (2019-11-25 20:54:02 UTC to ozerfurkan7{at}gmail[dot]com)
Takedown time:22 hours, 18 minutes Good (down since 2019-11-26 19:12:25 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-26this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 20.34%
2019-11-26Tcvai0ign.exeexe 2bd362b1b1d40dca063a8724598af78d6e5483a99519e48ba7a3b39391acd969Virustotal results 29.41% 
2019-11-26xNL3CSZ8czBKh3Fv0.exeexe 436c9af8ab6785139a8df7dfc3678a3d6045f6a8fda6707d1ba6f794c4f970c7Virustotal results 22.86% 
2019-11-26WZbRmgYDb.exeexe 7f39464941fea0aaabaf984b6e4714be0a248fe23f1c7454c9caf4f4112e7728Virustotal results 20.29% 
2019-11-26RVAYe.exeexe 903a8147323903519855c090a96ab8a01998fe93d52bbff743b5b1ebd96b5380Virustotal results 21.74% 
2019-11-25SCd61ZYn33EV8PH.exeexe 7013664f5297df77c2f0af1b9c9feb309eb406370b8278658cca7fdd43a3912en/a Heodo
2019-11-25Xjc2SjUcAt5rEwiBXFw5.exeexe 9d5d19879955b1f8040f5dc5e3f4480bf454368dd8e98099a720be2948b53902n/a Heodo
2019-11-25N13hXgIr.exeexe 02a16e9cd43bc1e5318cfca2cb07f79fcc9087469d36c429871a4f6733cc7cb5n/a Heodo