URLhaus Database

You are currently viewing the URLhaus database entry for https://ushuscleaningservice.com/cgi-bin/8s899089/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287077
URL: https://ushuscleaningservice.com/cgi-bin/8s899089/
URL Status:Offline
Host: ushuscleaningservice.com
Date added:2020-01-13 14:12:18 UTC
Last online:2020-01-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002241931 created on 2020-01-13 14:14:15 UTC)
Takedown time:8 days, 6 hours, 34 minutes Bad (down since 2020-01-21 20:48:47 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-1658Gg.exeexe 11c000cbc7ad1681ba7b7f529159582e4487af280875b72aaf52ca85910fae4bVirustotal results 43.66% Heodo
2020-01-146L8bLp71Vg3KQr68z1AgZ.exeexe ea2a39e502a71c09d5d7fefc48b2ca00f2196c42e3288299c69e7d085cdd6b46Virustotal results 22.22% Heodo
2020-01-14RGTDnwCkrbV.exeexe b0a59df4756ac630e6cdb6458a63cde0251b1284013a3d8f4f9a2025789fdb32Virustotal results 25.35% Heodo
2020-01-14uqW15jPuDBviQ2.exeexe 82749256f7bea612e1c338bac32b3bad58f0525c4c7fdef6cb87cc6e93d76c63Virustotal results 25.35% Heodo
2020-01-14zP555AorF.exeexe 60df4d9a82872456ed57a0e07159685ed4f9d7b89aac66c518b7e4843ab89ed7Virustotal results 25.35% Heodo
2020-01-14k4RM.exeexe 49041d079d8cb768bce72d60e0d47e47f22abdfafa493dfa9882194cf32696f3n/a Heodo
2020-01-149Eu8xklYn3BCJn.exeexe eb59fa820a73d9eef2a25cb63375376a998d46cbcf9a9ba5185b3b32535f9252Virustotal results 30.00% Heodo
2020-01-1438dp4t3EV76vsccDXo9S5.exeexe ec47408d09bddb18ef92e68ec7fec02e5485be3fa6f622d587c9d09490fccb06Virustotal results 27.78% Heodo
2020-01-147RmOrN8H5NKW9EJF.exeexe fd76a385819b537cd30cb8dccb8164e6646d0a618e10c73bbf999804ca956cceVirustotal results 26.76% Heodo
2020-01-1416f4ajGCAClDrC3j4Nn.exeexe f8dc6ef6b3cce570c6c9ad661feb3e171734a408c6cd559000baf7d5983ed5c9Virustotal results 38.89% Heodo
2020-01-145wah.exeexe 4954c405cf7c4fffc6600d299a088525850e4e37bfd63072ce34bc6751384b27Virustotal results 34.29% Heodo
2020-01-14F8DOkbf3Tjle6Ipg7QrX.exeexe 46ba3607d4d3c6f903b17635c3d082f91dae213d32eb7a21839e51715634cf0dVirustotal results 30.99% Heodo
2020-01-14D00iDwN29gY.exeexe e3b52f227944c583a454a8f274e5fd7f19a8e0e33f40c20c756f56ebd415fe15n/a Heodo
2020-01-143XUHI3qI60I.exeexe 615c7e989fd7bfb6889614ba2f4542ef6a6e8af49cbad782ca7d0859ca1abd8dVirustotal results 26.76% Heodo
2020-01-14Tkg0QVTkSuki.exeexe 81b8fd8242b55fd96e748ba8d922340f87302ce2cee62af8d988f001efbb8a8dVirustotal results 30.56% 
2020-01-14xHO.exeexe 93d44d4fca2903d1feb1e0a144f5e832ba66bfea2df7294196f574c0fccc8e30Virustotal results 30.56% Heodo
2020-01-14Dm9GvL2OHJvPrkyM.exeexe 9f2a7a094d9531eb0796088735ac9ce1f4f612a86a4c7f5a73838fdaf1137776Virustotal results 27.78% Heodo
2020-01-14rjea94MJ.exeexe 3c9000f84983ce11dc84ab4034b1cb9b5e16a18989e60e3b30cf074aad5ac29eVirustotal results 23.19% Heodo
2020-01-14tpgdf.exeexe f60c37046cafd42b329c6e0b5bb9e3976c21a042c0bfd87a1dede4f72be5f6bfVirustotal results 24.66% Heodo
2020-01-14Jjfyuqy7tg.exeexe cc6dd52a1966143eb5a9720f6becd21ac0de6e3cde84bee63a0d388aaf800a9bVirustotal results 23.61% Heodo
2020-01-13ft5ukECMLp8WMG.exeexe 52ffd67f1dfe0d6d0f56399cc869d090cfa2badcca485114012e3a4c17cd486bVirustotal results 24.66% Heodo
2020-01-13aPjGKEJW5q9nifn.exeexe a28dbcd19b2356dd8876cbfd49a371c536e7a4a82dff476658bbf4e64152626fVirustotal results 23.61% Heodo
2020-01-13PhbkvLK57py6ttkOLG2.exeexe 87602cb88a11f5c008e8725cc12de0fa5f8d883f94b44a92874df22568155f45Virustotal results 25.00% Heodo
2020-01-138TuMAqVDS.exeexe 745888bc231066bcc9fdad601c2fed958e876b881bd7fa56be8049626debb269n/a Heodo
2020-01-13NE1T.exeexe 3ec58af6e3cafa49b33a388a006bca231c48cfb8c96d73392d16df4cbd9469c2Virustotal results 19.44% Heodo
2020-01-13BMXQnUMqW.exeexe 53ba51c9c929a683cdcf3501418f2843d98b0142aa74c9ff69fbc670d55fd076n/a Heodo
2020-01-13Q4G.exeexe ba898fa43353a7dc577c32938973876eb2a0d9ae6cedeeb67947b67cb9f80924n/a Heodo
2020-01-135WSw.exeexe d0b1fba3b59d941353eb13058320542aec57d31e1ef5d41adc81d407629f9242Virustotal results 30.00% Heodo
2020-01-13mR6K7ZqTyeNfzWDjgqBG.exeexe 125f7c51507b088a78877c0d304d06d6f552b32ec963b7599aa142658c79fe01Virustotal results 27.78% Heodo
2020-01-13phz5zRwEIqlQzWW.exeexe b43692aef0f38bf8069b6f9ca113906fb633f402ed4ce213fa11e0a58627fc0dn/a Heodo