URLhaus Database

You are currently viewing the URLhaus database entry for http://www.emir-elbahr.com/wp-admin/css/1u8825/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273338
URL: http://www.emir-elbahr.com/wp-admin/css/1u8825/
URL Status:Offline
Host: www.emir-elbahr.com
Date added:2019-12-19 21:17:24 UTC
Last online:2019-12-26 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 21:18:12 UTC to abuse{at}ovh[dot]net)
Takedown time:6 days, 11 hours, 55 minutes Bad (down since 2019-12-26 09:13:29 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21H1PyU26nm50sWPA4lSOx4.exeexe def4e4b2e065512b7e15579a44d693a5a15892a6bb32d251b3f28c9e46675449Virustotal results 15.28% Heodo
2019-12-20bViQAbDgtr2Txit.exeexe d15e9ba56ee82bcf6ab3927e7fbf6a96dbfbe28e1babccdc4c506671f7347873Virustotal results 15.28% Heodo
2019-12-20MGiw.exeexe c4eece4b1e46466a25b6c57ddf3da8e880f3b826fe4493bec7b9bb8600363df8Virustotal results 12.86% Heodo
2019-12-20orCrN0HJutcsAe.exeexe 8182f4bfd12fafbfb2eb9c67bbf26053aa16df5326771e558de451c8e4e4781dVirustotal results 9.72% Heodo
2019-12-205G8G1XfaPmd3SxZ.exeexe c32979db48d4d3d02d674f884c0190eaa43305d00c4e8e1ad612246116ded3d4Virustotal results 17.81% 
2019-12-20uBvyA.exeexe 8c097306cb2d882685b7dc0dd52de66d0bf9cc99752934b13d81a5070e96cf8bVirustotal results 18.06% 
2019-12-20GiYuPS9v0znUXAkU.exeexe 1462226739fc93391f47f6bd506cdd6b993d66876770d47e69906559f0cb26a3n/a 
2019-12-20XIvx98.exeexe 93fcdd4dee62c753548f8f600600a485000453c4ad868c383d7be861f07b9ec8Virustotal results 8.45% 
2019-12-19hyWAcCwpfx.exeexe 69c9f973558a0e62168a9b4845c675aeafa531d3276e231e8692687108dd9df6Virustotal results 9.59% Heodo
2019-12-198JOuAFgmhQi.exeexe 8d86716678d921c652a5141ebcad1b872693d4596c330fd06b251e27dabf7dbdn/a