URLhaus Database

You are currently viewing the URLhaus database entry for http://fairfaxhost.com/Nets.eu/7Lzn9wt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:267638
URL: http://fairfaxhost.com/Nets.eu/7Lzn9wt/
URL Status:Offline
Host: fairfaxhost.com
Date added:2019-12-12 13:52:11 UTC
Last online:2019-12-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002164317 created on 2019-12-12 13:54:08 UTC)
Takedown time:3 days, 0 hours, 42 minutes Bad (down since 2019-12-15 14:36:21 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-14Q57q1we5hYNZ947Yv.exeexe 829d320a94bc45c699a4a9a1757b2bfb428ef54a80232b5dc21ad40eccbd4bebVirustotal results 20.83% Heodo
2019-12-14nZElRUevdsfqw9HZ7N4.exeexe b25c352aeedfe4e1d9d320bc137735efe9333c632e839eb347f0a1f5a99dccdaVirustotal results 15.49% Heodo
2019-12-14YwsHxItMptfXW8c.exeexe 5723beda11f2a98fac2c0e4be564b952a4e6314b143f2125d3288607cbde6cd0Virustotal results 17.14% Heodo
2019-12-14xq0RR3.exeexe 181a79a35af190ce05e5bac09e23d8670c247db0b55f465ff2af8c834e984ed6Virustotal results 19.44%Heodo
2019-12-14GNH.exeexe a9a4475887b141cae851bda64381dad964feceb2d61be9c99577a68ebfcc8330Virustotal results 19.44% Heodo
2019-12-13A5Aa6hhfExE.exeexe 39f7c5c06078d003ec402ec25eebf265a96b8714c03127e3078b09ae64bb2476Virustotal results 19.44% Heodo
2019-12-13cN4aZZ5.exeexe 83d35c434c05fb33b1531fed52fbe2ad53c3c49720a0c1219b682e96f467de98Virustotal results 15.71% Heodo
2019-12-13wCot8uoWc1RV.exeexe 3abe9af7c1d0f06477ed3d68081cec884cb792316c676b346a83014cd990942cVirustotal results 10.14% Heodo
2019-12-13yozltNlrky.exeexe a993cb9fa4c615bb7656a88f48e3aabbbab3dc2d851ddccb1b80e987a6e3cfc4Virustotal results 11.11% Heodo
2019-12-13jHW2h.exeexe ee27ce622d86fc20b1805c2ad66dd90bd7c235083e17217d38ee292488cb19c5Virustotal results 8.57% Heodo
2019-12-13Wf1jc1h.exeexe aaf3bcbffdc1f5c27eeba211035106fc1e0e5aef27bb5429c7e044a003318d03Virustotal results 8.33% Heodo
2019-12-13v.exeexe 21d345281902ff2e2f2dd1d335c9f0ce983f0edd7fa6eb03fb5713f736d431a6Virustotal results 12.50% Heodo
2019-12-13sIa.exeexe 34195a46c1eb277ab08e617054639bfdc6dccd7f4fe3c2f18189adfbca2e5dabVirustotal results 12.50% Heodo
2019-12-13D4FXfkDoISR2Kx3NP7.exeexe da4a44f3fb75590d494035fa1fc6df3a90cd9d39ad089726bd9b6cd1c8fdf838Virustotal results 9.86% Heodo
2019-12-13vw4gzg6I4K.exeexe d9a7f0ef3140c6ad0759c1fa89c6b387b482945c4b48341070ff3661fea36d07Virustotal results 23.94% Heodo
2019-12-138ITAPd8jERQLHGr5V.exeexe ba2b747fa1f40d0b82374d31b65ac4602f8787791042dffc6f9a159f5ddda8cbVirustotal results 20.00% Heodo
2019-12-13jhvuCF4CUVCh0I4Gz3cg.exeexe e60dec5b9eaeb1fc810b357a740e07e67c75f67195c5b3b99b105a0d9b858275Virustotal results 19.72% Heodo
2019-12-13S.exeexe 38f321e1d7367a1002f53d162279135440272af848efe75a6aab71f299599eb2Virustotal results 11.11% Heodo
2019-12-13MjDFbbNuX7ZHoeJKh.exeexe a193daffeebf7959a86ff843ca67a65253dffaac7c5cc15832c31822c2309902Virustotal results 3.23% 
2019-12-135dHv76U.exeexe 5eecdf69c0aad3b41b4310954423d85d121e962b631ab27b47ce8445facd99a1Virustotal results 8.45% Heodo
2019-12-13tAuIVfdgTF.exeexe e19158e6d8c78cd831df154b5fb36a779a033925be47374d16f59011617aad64Virustotal results 9.86% Heodo
2019-12-13zZxV0.exeexe 7c417ab5b89e38d7a4ffc306be89828e4d75f0b91309dbb89e65672738ef737dVirustotal results 9.72% Heodo
2019-12-12ivKomdZuOIH.exeexe f9cfd3aa0a37efc35ca5904c1950489b8d24163306ff00e4e3808a06a61dca9fVirustotal results 5.71% 
2019-12-12RlJ.exeexe 89e9ce29752cdd59a16269b8028b3b6b792615c2d6926892fe59da7a7fab34feVirustotal results 6.94% 
2019-12-12s9EJLgMfPhG.exeexe 4a4a409577731919cdb1019436085cef53d0c765e042e5d456fdc88e93b9d454Virustotal results 5.71% 
2019-12-12QMQhWSuhWMHoWNTq9tCf.exeexe 092eb30599685f47f849fbf78d7f2f60363e8e240c3a9544219bd3e03b710998n/a Heodo
2019-12-12vpXfkAT9tt.exeexe bc762aed5c64a3d3d4ddbc3406f36cb8cac182f2b40e873df558f391749a8123Virustotal results 27.78% Heodo
2019-12-12pR3N7Gd54Fj0AoQN.exeexe 45170dc1314f2a3b55bf530e4aea6b40e4973a0e84b46819d26fe7ef035345den/a Heodo
2019-12-12ik2wU.exeexe f83a4ea010f406408090c87b467704657211f59bb57bba6a3d1a5b2465ad6660Virustotal results 24.29% Heodo
2019-12-12dpHaAEAxr02NobhUaZ.exeexe b9a8f239f89b5e611992e8cd332cf36486109b25e1f29a79b95e255daa59747bVirustotal results 25.35% Heodo
2019-12-12jta24K3.exeexe ca8ea62f1c861b14af0ff7d6b1caab781585bbac4d8c12f3cfa38706d15bf39eVirustotal results 23.94% Heodo