URLhaus Database

You are currently viewing the URLhaus database entry for http://vikstory.ca/h/f2cgRvw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:267451
URL: http://vikstory.ca/h/f2cgRvw/
URL Status:Offline
Host: vikstory.ca
Date added:2019-12-12 07:00:34 UTC
Last online:2019-12-28 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-12 07:02:03 UTC to dnsadmin{at}alchemy[dot]net,abuse{at}alchemy[dot]net)
Takedown time:16 days, 1 hours, 2 minutes Bad (down since 2019-12-28 08:04:43 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-14Q6pH6A.exeexe 181a79a35af190ce05e5bac09e23d8670c247db0b55f465ff2af8c834e984ed6Virustotal results 19.44%Heodo
2019-12-14SykLQ1whNVyMq.exeexe 37e46025df39810900dacac8f43f3eace6d7b46f5e9d65f143e493812eafd5b0Virustotal results 21.13% Heodo
2019-12-13Hmpx1rVg31yzIsfAW.exeexe 39f7c5c06078d003ec402ec25eebf265a96b8714c03127e3078b09ae64bb2476Virustotal results 19.44% Heodo
2019-12-13v1L9kyKupGQvCMpn4.exeexe 83d35c434c05fb33b1531fed52fbe2ad53c3c49720a0c1219b682e96f467de98Virustotal results 15.71% Heodo
2019-12-13gVQ8a6sPGUaxFyk0.exeexe a9c921cef7ce21574274ec1455f5aa333b669d5e446b102a15a1207ead73fcd6Virustotal results 11.11% Heodo
2019-12-13lOllwiw00t.exeexe 8ab8b99b0f429e08666222e87dfc71c81bf544a7a6a1bfad21c2c840d9cc73dfVirustotal results 11.11% Heodo
2019-12-13Ia5EGwNPtad1.exeexe 4ac582cc94a90c7e6979e5a09c10becbddf7e61738df533e572f4bee3345a95eVirustotal results 12.68% Heodo
2019-12-13Q3OONJ00aiVCoT.exeexe 0404e61ebbedf9973dad4ad2efa2d2d933ac14c475f8401d262691169d0db414Virustotal results 9.86% Heodo
2019-12-13IOywiFUrUM3IeyngM.exeexe eee9c450e2e35e2ab665f091617d3692c6d5bc77c7e1d40f5968d8037129ba85Virustotal results 13.89% Heodo
2019-12-13TIXeVCU5231.exeexe e04b159f524bc5045a34f43c9ce828e801ec4d29b1b75a6c15a41c26d8ce6485Virustotal results 8.45% Heodo
2019-12-13TQh3hLZ7B75P3mFa4xt.exeexe d9a7f0ef3140c6ad0759c1fa89c6b387b482945c4b48341070ff3661fea36d07Virustotal results 23.94% Heodo
2019-12-137OuLep7WtFTT.exeexe 99910edd900e32a67cf5dc20ae07126c5755a6f564f39ef928be13e33fc406b5Virustotal results 19.44% Heodo
2019-12-135sFvw4b4sOWw879q.exeexe 5705b56600fdab0c97635626650f213cd73b4da2e37ac7ae908d63919ae1c198Virustotal results 19.72% Heodo
2019-12-13ff6ugMAU9uuM.exeexe eaadb7204bbb14353f54142dd85492d579cfdaf9b005b3929d4d8ecc26dfacc4Virustotal results 12.50% Heodo
2019-12-131.exeexe a193daffeebf7959a86ff843ca67a65253dffaac7c5cc15832c31822c2309902Virustotal results 3.23% 
2019-12-13qRXXUOVmArbNf.exeexe 80b567682429f8bf105acbf47bd31ce1980f0d240fb4fec1ee6a465663657f65Virustotal results 8.33% Heodo
2019-12-13P0619T5Y1r2EcIFWM.exeexe dce31492a93bb5936e6768be67a4f42f92c3b81a1cb9dc84d72993476de47374Virustotal results 9.72% Heodo
2019-12-13B.exeexe b44de9b2eac858c80552c9b136127d791951583794541bb33f7011764af1a2ecVirustotal results 8.45% 
2019-12-12p6S6vdIVyB7az.exeexe f9cfd3aa0a37efc35ca5904c1950489b8d24163306ff00e4e3808a06a61dca9fVirustotal results 5.71% 
2019-12-12DGY0mMZagRw.exeexe 85cd2d8cf5570a1365d081b3c301eef61dca7247512c86a7364add60cc106cfcVirustotal results 8.33% 
2019-12-12853zB8jKtm.exeexe 4a4a409577731919cdb1019436085cef53d0c765e042e5d456fdc88e93b9d454Virustotal results 5.71% 
2019-12-12AZbI7.exeexe 092eb30599685f47f849fbf78d7f2f60363e8e240c3a9544219bd3e03b710998n/a Heodo
2019-12-126dZf8n.exeexe 486937e299fc0abb53a4df9974011b992b044ccb95e7c0a341eeadec03dcbcc1Virustotal results 26.76% Heodo
2019-12-12Dn9x8D68jxfYml.exeexe 7a56987998881603b06adf1ca632ed09ac531ccc41e53f82256c59f3165ce94cVirustotal results 25.35% Heodo
2019-12-12wNhIH.exeexe 5ebf87819fe3c6834f2336a84b87bb28b5aa314d11d3fcde938d3456f61a2e42Virustotal results 23.94% Heodo
2019-12-12eGMOTEta.exeexe b9a8f239f89b5e611992e8cd332cf36486109b25e1f29a79b95e255daa59747bn/a Heodo
2019-12-121bl2QVIKxDfo9kjCd.exeexe f67d3108528ffd5edfa4f64f803150b515625771bd03ed5032640903d8ae73a0Virustotal results 21.13% Heodo
2019-12-12JboET7WxleimX.exeexe e65cac78e59f17174d7d768443177c3bd9722f3f78c34b6fa6f5c91895cc7935n/a Heodo
2019-12-12laJAS.exeexe 093ca9131f4f73ae73f037df072479cab48fd3d4e2610a8a2951c3d39302152an/a 
2019-12-12KH8YICCy6EyfULRh.exeexe 7c04a44f0aff396dbd219ad62ce723f15f2f001d570bf35babf5bc2a6a7c1b5aVirustotal results 23.19% 
2019-12-12kw.exeexe b31c55a2891ff173e187ef01e19af692f065719a8062fb47b5cb5a6d5d024d90Virustotal results 22.54%