URLhaus Database

You are currently viewing the URLhaus database entry for https://prasannprabhat.com/jetpack-temp/VRigI8ssAj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273233
URL: https://prasannprabhat.com/jetpack-temp/VRigI8ssAj/
URL Status:Offline
Host: prasannprabhat.com
Date added:2019-12-19 19:51:22 UTC
Last online:2019-12-23 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 19:52:06 UTC to abuse{at}automattic[dot]com)
Takedown time:3 days, 22 hours, 5 minutes Bad (down since 2019-12-23 17:57:47 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21ApG6roWnYY.exeexe f86a2882452a6a3b7c33a7a5b7a7e129631dd6cef8b70412e4b7e0fb4da8e659Virustotal results 25.35%Heodo
2019-12-20avZrtoRPVIlRVaC.exeexe c4047152a0f228e55fc0748cd21a0bed309c32fea414d22611b6eb3be9d3c304Virustotal results 16.67% Heodo
2019-12-20x9BKU8zxl4m8ggaWRxTJ.exeexe 860811a83182ade41798fa04af0fd5b0fad475f4e5a920620978aa265cd46e83Virustotal results 12.33% Heodo
2019-12-20GD3tOa1thz7E4VS7C62t.exeexe f686b6f638e28854d1f0bbe530c09f0290390ceeb0fbedcbf567c86f4ec861f4Virustotal results 8.22% Heodo
2019-12-20gpkr1aXYhZ.exeexe 2609ac18c14c67fb61e6a5daa14ac32fe8a1868d8a29cd27e05b6ebfe850d98eVirustotal results 6.94% Heodo
2019-12-20BEPk.exeexe abe16ef51275f947ea69c98e766738cead482cf982642f861b41e557ca2512eaVirustotal results 5.56% Heodo
2019-12-200q8dQJpXVmICQPb7.exeexe b71c8e94aab3bdf415fc0f1c759f737a04143c24749deaa870a98d4cc8c0d636Virustotal results 21.92% 
2019-12-20c9Rw6OOSxLX.exeexe 2df602dc5e37833439f5cdfe569133e1913dda008f1d4f2b0e140851d5cba5f2Virustotal results 18.06% 
2019-12-20uxslNpnWEUyM6mv4.exeexe 160fb36d9c59d84efa13d0efb29db6024e0d128876ad49e71f0438ebd2693733Virustotal results 12.33% 
2019-12-20H9Dxo.exeexe b96d75d71f18f32a1f4c303afb5bb5c3c04b950768c2473aa5d3c23fb2929384Virustotal results 10.94% 
2019-12-202QUgWpvCHxGWTJOWEsu.exeexe f325b82278c44c75b7be14b685bd7ed01bc17bc58e61e7c613f68958eb90c32fn/a 
2019-12-20CYHLVRORNBk6POYtFN1.exeexe 1d477b29e772869de816443a1d01bbb7f18d5a1c202134ab1ae23816a13ac8c5Virustotal results 9.59% 
2019-12-20MqXnGBUh980444C0w.exeexe 9c5cdfc2e2d2c85218a414bb86f6f45a91c99b8707dc3ff3294df8d9da3c9f73Virustotal results 12.50% 
2019-12-20Ix.exeexe 944740d6173afa86bc648d7bc0be732ab8cdb7c12e0ee8a849c109d9317eff95Virustotal results 12.33% 
2019-12-20xVggeBEVK.exeexe 3c7511c35188e5f79b3706c9eb4c29cb46bf89d40a922d1e8c36e3f16119d0d6n/a 
2019-12-19Wf9txwXqOSgI88z.exeexe 2269983ea31c8cff65fe7c63a7d5d5a52bba209cc62e999ae36e59430b89b14bn/a Heodo
2019-12-19kAptcAVlPvpTTN.exeexe bbc109117d35dc346fe3391051b0011742be1fd470e829455fe4b11dc2465995n/a 
2019-12-199lSz3VCC5kfADWzy0.exeexe a6814254db9576b400fd5eeac2157060340f2d9807d1ade6248cdd2a48edd7adn/a 
2019-12-19zbgOJSBX0Op6.exeexe 087bebb1c762507b7f968943f117cc57a7e12f57f4817876ec88d2b5620cc2e2Virustotal results 14.08%