URLhaus Database

You are currently viewing the URLhaus database entry for http://www.rishishwarfoundation.org/afx/52rs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289485
URL: http://www.rishishwarfoundation.org/afx/52rs/
URL Status:Offline
Host: www.rishishwarfoundation.org
Date added:2020-01-15 23:21:12 UTC
Last online:2020-01-30 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002249091 created on 2020-01-15 23:22:07 UTC)
Takedown time:14 days, 18 hours, 25 minutes Bad (down since 2020-01-30 17:47:42 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17q.exeexe bb47036d56346de76c6e066bb8331e756835c361fb0c562beb090082f74b451fVirustotal results 13.89% Heodo
2020-01-17h4mhQsjE.exeexe 7929bcf5abadda47da3540dbbb09514a9e90b5cabc47af28a2fea6a43c98a704Virustotal results 9.86% Heodo
2020-01-17sPSYsZsPdw.exeexe 1fda1557f85117f8d7f02cf8d2ff1d5d998318dc0cc10b4c425584e4a78d97fbVirustotal results 15.71% Heodo
2020-01-17myTg5.exeexe babee3681f82b909b44e35730607910aff3d5bfc2b539a78bd1e80d12c4af3bcVirustotal results 11.27% Heodo
2020-01-17qa01Xu15WO2wSOQK.exeexe 44de1fda3315e9140ee467547a856e9e3c7f5f683b22b852590f69e2327be269Virustotal results 15.49% Heodo
2020-01-17J.exeexe f55fd46dc456c4064c0a54f7726d7a9df6d6742baf3c58ad6ea0391be9da4fb5Virustotal results 12.50% Heodo
2020-01-1755fCllcsn5bd.exeexe 6742c01a902c1343f272b2112d8bc7cfe6264e853304f4ade3349391e7141ee9Virustotal results 14.08% Heodo
2020-01-17niW0BHfJfA2OeuFE.exeexe 44d4be0943c71e9102f36e2a92318e7f66e863a2b0baeb7a9bc9468ff3c5ed19Virustotal results 8.70% Heodo
2020-01-17nElUgB.exeexe 4e93e415faf5348d1d25f9da8c96e7db1a329cdd9dcd11144357bacf592215b0n/a Heodo
2020-01-17ZTq.exeexe 54347108ade6b323b3d4308467479efc1b92b5f7627673681fb07c5dc1d3ad14Virustotal results 19.72% Heodo
2020-01-17OSlA0mMPh44.exeexe b2b6388b0e753282f8cbdb0b95f65735da1343dcb4ccd5eebece6d37270a52c0Virustotal results 18.06% Heodo
2020-01-17v1ngDnW9j0JhC.exeexe 6cc238a48d512bbcc005f5a54c4aaee33271f7f0bfbc530d7ecd0c9abf57a80aVirustotal results 26.03% Heodo
2020-01-174bKGz1MisyTp.exeexe 3124ffe437bbb59c83c995ef9f3ed3fe2245b518ab7fbb698066b56a6d95209fVirustotal results 26.03% Heodo
2020-01-17FauAD73lWe.exeexe 33e1b8b2d4d08ff986299f6e20ce6a3ffc2221c634c925ffacb112868c4a19e6Virustotal results 28.17% Heodo
2020-01-1766V4X7O6CQ.exeexe de9cb06f374dc761178cd19ef6b16dfcc09e204b6b6b293328ac8d4f5ecdc01dVirustotal results 19.44% Heodo
2020-01-17lSgW.exeexe 0f540b87389cbf4df0fc4329de3a4ce274cb80264aef9052f3501c538a8af6bfVirustotal results 19.18% Heodo
2020-01-17spGDyyasFlV7Kk.exeexe 061a0342f5677a8455bcedcb93aca3ead080b2ab737d5152d8fd75b54ea919fbVirustotal results 18.06% Heodo
2020-01-17CaI98TGH22Nn1o70sd.exeexe a39906f3efa59ed011ae37b19d39a01197b5b7614e17aeea548f6d11a61b6285Virustotal results 18.57% Heodo
2020-01-17208OzeR8mg3XtR2b.exeexe e3b1ee8134c713e8e6524bf1316bc585249d235413df0f93bfca603d321f9c06Virustotal results 15.07% Heodo
2020-01-16sh9yKIMtUsU9XKgvXgG.exeexe 9b9570514af4fb139355d142d44c7776e33635e850429e2b3f4ab4d385e7eb32Virustotal results 12.86% Heodo
2020-01-162sI38LO.exeexe 3bcaeaf92ef41b08b0415a7e0b094762ca88272627f9b10483dff29c0143f138Virustotal results 9.72% Heodo
2020-01-16Fui.exeexe dee4ca89cdf2a4b0d90ce6ec9b7de9d2525b3bb2c82b39f93cb627e98be34641n/a Heodo
2020-01-165ssnw.exeexe aea7a784f4d4abb91342c0bcc6c4539b5517d3f75020e8aaf94ea049b92c6aa0Virustotal results 13.89% Heodo
2020-01-16ZqOVnu.exeexe fcb57076271ad2040e47e091a984c0bd98f997cb2326f90dc83823e1b169fed9Virustotal results 9.86% Heodo
2020-01-16TEJJJWCxbxMu.exeexe 1fff2de5a03d6b560fcf0dc1cdd3405cc3fc4b7d1bc515118dcfd0c09e52f597Virustotal results 11.27% Heodo
2020-01-162yIJGBVSEQD.exeexe 176fa94452d5dfb15d0c0cd5c8079ceb6f72f26339893d6d86dcce7e2a978860Virustotal results 12.50% Heodo
2020-01-1603k5m5BvwiG4gs.exeexe 298f5ddc04f75a5db9261d80691906c3151727d0524821eec0b2d7689a14fa51Virustotal results 9.86% Heodo
2020-01-16h3.exeexe f56b18d4ce473dd74391e302d1a162050cd2854ef3465c64f2cc0d90263982ecVirustotal results 9.72% Heodo
2020-01-16HL6Cj2DD8tBz35.exeexe 563b3dbdb51d73d2c17a968b03df80cf92ce16fe74435e6defb110cad1d6d629Virustotal results 6.94% Heodo
2020-01-16oI.exeexe 045ba8f8849deeec34751520cb26efb1d43c4e72b70171a319fc2a6ac157e3b5Virustotal results 6.85% Heodo
2020-01-16ZaV7iwZp3nzIPPJ3VOJJ.exeexe 68109f79d9c1d3a197d3ffb7dcd3519261b083d4c7ab5c4c13611055c4abc3a6Virustotal results 7.04% Heodo
2020-01-16hyTG.exeexe a6a1859f3f10313bee5dc8bd44ce4bb0558b1d2b714d911dc33e138c48e1b737Virustotal results 4.23% Heodo
2020-01-16KWl0B6GAKLZr13h80.exeexe 4ea119890e77a3f78c0fe42d38d204cc1d641398c8b98015902d0b55dd981e74Virustotal results 5.56% Heodo
2020-01-16TVby8oreruqTo.exeexe 59ae3f034ce0185f8bd0711537f4d590459bec9b2a3809e75ca2030bcef9c3fbn/a Heodo
2020-01-16XChbOVQNuAAox33F.exeexe 5caca9f7b8847833ea42f09aca955d8a9d69ea5a2386ec4b25d206b1d23ee449n/a Heodo
2020-01-16uR6JGGLI5XZlZUaaqRL.exeexe 184fa46f862078b2a13ce3541837fdaf3840091b8dc6f867557132a471cc7aeen/a Heodo
2020-01-15qmzD5.exeexe ce6f95cd098a60d4861ec723edce1b254af88b64cadeaf449bf82658247f657en/a Heodo