URLhaus Database

You are currently viewing the URLhaus database entry for http://himalayansaltexporters.com/photo-gallery/QWtpsvaVR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288114
URL: http://himalayansaltexporters.com/photo-gallery/QWtpsvaVR/
URL Status:Offline
Host: himalayansaltexporters.com
Date added:2020-01-14 15:29:15 UTC
Last online:2020-01-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002244586 created on 2020-01-14 15:30:05 UTC)
Takedown time:13 days, 2 hours, 25 minutes Bad (down since 2020-01-27 17:55:53 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-20yvy2wkx45905506.exeexe 60d8175e0a4a6e115ed79800717cc27bd3e8d8b88af2f81823623c1b3fead089Virustotal results 61.97%Heodo
2020-01-167660zdjsl83848.exeexe e40c8129d918aa360b36644f2b74640443f60c0bc3e4029c1a57a767ab6431a6Virustotal results 5.63% Heodo
2020-01-16rjr544190705.exeexe aad8ed58a735dfbc1d3b25531f8941882ddb97b29c2ca66d698ef554473848aeVirustotal results 22.54% Heodo
2020-01-16cucemph5u01069882.exeexe f2ae96a761c4bda5db63c06bb71bb0c1249bf81a5243fae1e037a5029405bf98Virustotal results 7.04% Heodo
2020-01-156o358764595432.exeexe 8af22dbae21ef24749b527ea23c8efa0acd3830f65c0f58b8ae980909094c376Virustotal results 2.78% Heodo
2020-01-155s73612520.exeexe 0a9b06b95b2d00b1b6c4c2f691937bcbe52a826b2e17fcb6fd0c355483622e4cVirustotal results 12.68% Heodo
2020-01-15dfyvq6pl317018.exeexe 438a9776c74380d9828530575c7d9af224842d7b35e24e2d76fd35a9622b8248Virustotal results 29.58% Heodo
2020-01-159t38.exeexe 5896012fdbd6280c6f4f30c2a5d5429aa175fd3570e1f7fc615a99e05ca8c5e5Virustotal results 20.83% Heodo
2020-01-1587g78268194.exeexe e8ab38e56796caf4020112ededb40e092353e26c38e8142f19b1af9a0a4d36d8Virustotal results 22.22% Heodo
2020-01-151gynx529z75932.exeexe df702efe3278aef7629f5e411084a8360b18c9666d37f8c0854dbe0640a51f75n/a Heodo
2020-01-15mror399063.exeexe 77e4ff4c6959d605d4f2ea9e9e3c107d1bcbb481e7aef788abf2cbac98abfeben/a Heodo
2020-01-15fwj56939766.exeexe e81015d996de95980d2cf710659e7350d33afd73ae843bc4587c7ae581a6919fn/a Heodo
2020-01-15bzkjagduk3.exeexe 94eb27f76ac065504d5e6412f5711030a2ad1dcb913b58313088f708ceeba812n/a Heodo
2020-01-15re0c68419.exeexe fb7669bdc32501ec840a785e820735a460a53aa99e0fe8b193ec8d6b20f428f3Virustotal results 24.64% Heodo
2020-01-15u1q53hi6.exeexe 500407302680487e6a8aa44c221b5f5dca9a6b77feacbe30f5d1fd441633ad3cVirustotal results 23.29% Heodo
2020-01-15m03cqfx643936.exeexe 23b34d238610db6686755a470e24ce2de3a12f640413092f56fbba1bb6615fb4Virustotal results 32.88% Heodo
2020-01-1561z45adff355250.exeexe 855fab1f523dd047f98f3cde8c69ce9748d90ba3668480c2e48d97759692c960Virustotal results 32.88% Heodo
2020-01-15q55211907.exeexe 8307b9abb9c8ee6769faa4639fc5d8ca524328d56e48ab8288e47d2095e667d1Virustotal results 30.56% Heodo
2020-01-15od43hcz71.exeexe e0e7a946cc8710c4d50388932b9207f50644bed3456856ca55934989dc2f3747Virustotal results 30.56% Heodo
2020-01-151vnvy03.exeexe 5886ff51331f78c2f1d16017f9a0a45928198a6602e2ed46eafb9e18f1a9e37cVirustotal results 27.78% Heodo
2020-01-14jwt9a86.exeexe 85cffa7299b26efe25d352a992ac60382440947c6815882661f0049b2446710cn/a Heodo
2020-01-14lyzv07.exeexe 97a113e1d47f52beb1f8c6b76be5e0a02c75ac90d486e8b5883a6ebdf39c6172n/a Heodo
2020-01-14aty7h4zn358477.exeexe 043ebecb992c949f92aab7839468b721b409cdbe1d7af96cbd223af186907f83n/a Heodo
2020-01-144f4c654599027889.exeexe 1d3201a9c232954429e69408949d4b583e490bb18a02c67f1264fe5e8906adfan/a Heodo
2020-01-14oaeb5jdlk520137821.exeexe 3411b358cf2fe429528c8cbbbc7e464a7ecd36a481cffe1850d907d36eb4e43an/a Heodo
2020-01-145rx0uzz8xj5435.exeexe da08a98a2bbb13f37284dbe3691a231f7ba79e032902d8ce75ea7987e28de593n/a Heodo
2020-01-146bllavl9l517.exeexe 256505510b0f3953c40939ab2e6313d6dd0a610949fe8cd09a5cdb12acb82bd0n/a Heodo
2020-01-14d3qun8101024.exeexe 4775195701f6604aed9d93f712feb5548d7b4d829d2fb99e74389d84b3f7d5b3n/a Heodo