URLhaus Database

You are currently viewing the URLhaus database entry for http://baute.org/64/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:27389
URL: http://baute.org/64/
URL Status:Offline
Host: baute.org
Date added:2018-07-03 08:10:05 UTC
Last online:2018-09-08 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: oppimaniac
Abuse complaint sent (?): Yes (2018-07-03 08:24:41 UTC to ip-admin{at}coloquest[dot]com)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-04201.exeexe 07a2a449026acd0e941bfc8138266a5399e5a78f6ce5dc926a30d45c41558f11n/a Heodo
2018-07-048004.exeexe 8989772e5c3181af828dc4f3e85a0d8308df5263248b9a96a0ee50b3c2691e46Virustotal results 20.31% Heodo
2018-07-0447.exeexe 78d4b80761fcd9078b54d165f0a9f390f92b5979495afb85b45a06d66ab03f28Virustotal results 34.33% 
2018-07-034664.exeexe a97c91da83976d5fa7692f560c421d7c8d9e2c7b6f293f9a158045ae2a1fb3e7Virustotal results 32.84% Heodo
2018-07-038712.exeexe c368745cde7be79e82780c18baa26d376946c0852f14cee8fea805e2019b2101Virustotal results 26.56% Heodo
2018-07-0368.exeexe 8a9e4c49606ad76693ebb05a929b8a652d0b3945f5d62c4b937926c0aa6a6e89Virustotal results 32.84% Heodo