URLhaus Database

You are currently viewing the URLhaus database entry for http://classywonders.com/web_map/fsrm01124/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:261308
URL: http://classywonders.com/web_map/fsrm01124/
URL Status:Offline
Host: classywonders.com
Date added:2019-11-28 21:46:15 UTC
Last online:2019-12-01 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-28 21:48:08 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 days, 0 hours, 25 minutes Bad (down since 2019-12-01 22:13:47 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-29p0ii2uszow2k.exeexe 0337c585532a4a3cbed48602fe42563e965b8d853432391633e1da888f1946e3Virustotal results 19.12% Heodo
2019-11-29kvvmi57hy22f4.exeexe 410dd05fb16ec48728cafc0acd7a0aeb0535df03fdb7c1377316a5bacc58eb54n/a Heodo
2019-11-29job6s.exeexe 5e868b41f74af9d6ea84aaf22f71418a05a1f7b7e403d2974b08f0d4de6dbb2eVirustotal results 15.71% Heodo
2019-11-29xjwi9yd.exeexe 32970751598ac2a109df9d9d9c56a9529a5023b4b2d78080193ae1666d58cccdn/a Heodo
2019-11-29pk82w0ujiu7u.exeexe ddfe799b8016a219d9ffa94ee3dac44de4a100057364b30c313c00ae36052c54Virustotal results 13.04% Heodo
2019-11-29ahutc6p.exeexe 23a62b95fe0da2a84e91a5c4f9661eec77342db43a2c4e4463cb19bba14c70e8Virustotal results 15.71% Heodo
2019-11-291205r442mq.exeexe b1a732d312a675454f5ee18927f247576bd9155841552d7e80802a9b86bf5247n/a Heodo
2019-11-28i98xs3slilq.exeexe 4fe8b272f0b976a2b0a504f96ad7be8bbf5cf4501d2148b64bef85baa240b5a4Virustotal results 14.49% Heodo
2019-11-28qda8rgntsu7.exeexe ffcad973d390937397bc4fa95825d7939150eb223b6e6486cbfecbc0b712903fVirustotal results 13.04% Heodo