URLhaus Database

You are currently viewing the URLhaus database entry for http://meert.org/cgi-bin/DrjIA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272590
URL: http://meert.org/cgi-bin/DrjIA/
URL Status:Offline
Host: meert.org
Date added:2019-12-19 06:49:07 UTC
Last online:2021-03-17 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 06:50:04 UTC to abuse{at}axc[dot]eu)
Takedown time:1 year, 3 month, 3 days, 21 hours, 16 minutes Bad (down since 2021-03-17 04:06:22 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-01q3XITZFcS7jOTial.exeexe f10052e10c319749ccd6aead272df3e831e4d4224a32ac589e1a577db38e2b70Virustotal results 69.44% 
2019-12-2011zLogZBdtlzn6.exeexe b9df29fbee79903dfee1f016e0b5dd827d47e34c41aa1162040aa3e61f6a2d33Virustotal results 12.50% 
2019-12-20yy9cU.exeexe 69ed4bf7095c2d6d34586b85b2560885dd9511b4d7d6a9bfe22afd0f2bbece5dVirustotal results 12.33% 
2019-12-19IlPpax9rQhll.exeexe d52c3376c1b55909f85457450804318ac8962268592d8b5aab8999c8ae16a06bVirustotal results 11.11% Heodo
2019-12-19fdkZPauJ4trz.exeexe 4cae3f1eff35915a02123b4dea80da4bb144f6dddb7507d35bcaa912424ebad2Virustotal results 8.33% Heodo
2019-12-193BLL33mhC.exeexe 43f2d883012acd85d9e323eaef569d9bce412e36e0302cc94a62862c3e6ce311Virustotal results 22.22% 
2019-12-198yWzI1PfyYq87JKpklM.exeexe 087bebb1c762507b7f968943f117cc57a7e12f57f4817876ec88d2b5620cc2e2n/a 
2019-12-19VJ4VfVr.exeexe e584a810d9862647ca6ca6a0cfd5b2780957301f36b450d15f5908312ac91f66Virustotal results 15.07% 
2019-12-19QpEVE79vIe0IUd.exeexe b2e73a8a0617de9dfbcdf69f031ac91e4c1a53d58217e04dfa85bc0997273245Virustotal results 13.89% 
2019-12-19AcNB.exeexe 026c02ca98371d7d8f0e5127034064f3bb70410340cb0f1f2d7e4fc45b86a33dn/a 
2019-12-19cc.exeexe b00620fd0470068d3709c5cd6e78e93f543317943a84265edd4cb74ff018c83dVirustotal results 11.11% 
2019-12-19QUGhIB0x.exeexe 49947961c69fc1c2d7709c73f02ef20ceca55fa60028d871c796d80a4cfc06fcn/a 
2019-12-19DgV.exeexe f5085366e761c1d60d3c423ea34a455a877fc9e0019915c43bf905d9a5273d5bn/a 
2019-12-19POG3qbUJe.exeexe 96977039f2a2efc2ec8a9fc7cc6e3a0ea908bffb3bd8c439540a50315ab95078n/a 
2019-12-19chvi0NkQmJEUSz.exeexe cec71363ef6333d5b02bdb99ca4122c9fa12bdd097358e92a9b572c01d5fe19fn/a 
2019-12-19Hdn99gs54rRFS.exeexe 976be839990f7bd3c5c87d25087e8a69461c77f409320d9e06abd5b9b3d6379aVirustotal results 16.90% 
2019-12-19ddqFT7xGZV0.exeexe 5af8a65ab2ade1f7bf67f1ccd7825963db34bd93c8e1fa97144aab0bcc42790bVirustotal results 22.54% Heodo