URLhaus Database

You are currently viewing the URLhaus database entry for http://amelano.net/wp-includes/css/dist/2ew/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290411
URL: http://amelano.net/wp-includes/css/dist/2ew/
URL Status:Offline
Host: amelano.net
Date added:2020-01-16 22:55:18 UTC
Last online:2020-01-23 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 22:56:03 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:6 days, 3 hours, 23 minutes Bad (down since 2020-01-23 02:19:33 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17nfDJUz.exeexe 549d6b00fc46124be23e3e6b78f751b917683e29d7e6eaf96d9b1ea90123e276Virustotal results 24.66% Heodo
2020-01-17nD3IQMojAL.exeexe fe6b3c11879bbfa61714c884476c9e03d2445957e30d36ea1492a9b3357dadb1n/a Heodo
2020-01-17I.exeexe f432271a02a585d701f82e7c8bc9ed9a929d644da05ba38f0b281e585da6aafbn/a Heodo
2020-01-17cj7q.exeexe 035a69580d783b6027b9d5a6f088bfcc1c296921e923a6793aae6bc972c294d6n/aHeodo
2020-01-17yZXAEfF9GG9UJj.exeexe b3e2fada8c31f52c2657c8a4ff0f63af7f1f5a1e788d14b9426cee389ce71198Virustotal results 19.44% Heodo
2020-01-17h7BfZH.exeexe c64b34d2f1b0ae083b6bb3457c6f0a8e8360cc9e8533460b9e70932d01a75288Virustotal results 18.06% Heodo
2020-01-17NWxX9dNJmbRNgjH.exeexe d4aa4ea864d096e666d6f8117b029c8a0728834460d5f2c7cfabdfd96fa38479n/a Heodo
2020-01-17Q.exeexe f86a74890de3b46097c43b70f919fc53289e732d2cfcfcefb4650109d7437a54Virustotal results 10.96% Heodo
2020-01-16hXSQiQn2qf2F6lY.exeexe a157bdbba3af072f41ae05241dad29833b89fcda2a4d80022a6e6f7b6c25dba7n/a Heodo