URLhaus Database

You are currently viewing the URLhaus database entry for http://rcmgdev44.xyz/cgi-bin/rossN32/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290702
URL: http://rcmgdev44.xyz/cgi-bin/rossN32/
URL Status:Offline
Host: rcmgdev44.xyz
Date added:2020-01-17 06:58:43 UTC
Last online:2020-01-19 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 07:00:03 UTC to abuse{at}digitalpacific[dot]com[dot]au)
Takedown time:2 days, 15 hours, 33 minutes Poor (down since 2020-01-19 22:33:25 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18g6BRXIAHGQWI85kQ.exeexe ab5dc331127be64fb5120501c03de22a819a9ad88d8e17a8cc04e709900e4f6eVirustotal results 26.47%Heodo
2020-01-18uosMkfn5WhaQW8VI.exeexe dcb01fdf8ba270d3dd024fd60a28b21f0dba6ba8624dba1207e867a13085de7en/a Heodo
2020-01-18r5U96yJllc.exeexe e305d29476a1431019e8f7b2d960c06cac5075c903de497c78a27f83d6492ec8Virustotal results 15.28% Heodo
2020-01-18OjJLcX1c8IJbbXhDQi.exeexe 7bf06e09cb28c2e0adef99dc5de4a4d013f88bba7ac5123ed6e9eeac9654b3d6Virustotal results 12.68% Heodo
2020-01-18DK5.exeexe fa8fb602ba4f5215a45d3d4aba985136d7f6cf1685fd8b23c5edc9f1b7f4d33fn/a Heodo
2020-01-18dskl2xZC5PYGNGhey.exeexe 0fcaed857557244561f11984d7771874aebacc8f84f4e0280fd3c918d6c68d1bVirustotal results 5.56% Heodo
2020-01-18Jq3jdqAuhEhM98SZtCej.exeexe 8a005cf6c3fe4f9cb08eea708c619dcc9c5c8ca0df93e5961b0766c2e6733f1dVirustotal results 6.15% Heodo
2020-01-18YsSd2cgfS02gACLmk8.exeexe 10274ec59899011e808ab76acba60b1e3caeb34a7007da3d7257e74908a92a10Virustotal results 13.89% Heodo
2020-01-18HMSvih7NwPM0VMN8jH.exeexe e685c407341b3175562635b2e2f468d8a7d53e461cc975919006a3776f709d30Virustotal results 9.72% Heodo
2020-01-17aXa81rwxAE.exeexe 0c6a5cfd8f4fedddbe98130c44c7066f8d5408be546c3e9e65c32bfa96768c12n/a Heodo
2020-01-17bkGQFB70g5XsNK.exeexe db2bee558e44f6b3779eaeed1f8b6cb320d6bbcdf062a3bd4d745a24148291a3n/a Heodo
2020-01-17jaF0t1cFJCVi4fl.exeexe a0a2adb4aa63df59ec491842965efa9301e8fb301d2ea58ada83067719148c38Virustotal results 12.50% Heodo
2020-01-17jgLtvnJPtYOR.exeexe 5057702a905c8d2827b557d15963b3e32bcab7e10e31dcb5dee44ad3e6aa5a42n/a Heodo
2020-01-17rwlJSlSLtn.exeexe 54e1b3d2b09af635b4fb96b871f61ddf64bee455441407200c8345dd0d2d92b5n/a Heodo
2020-01-17jfk7K.exeexe 2e1814e7d9a588824835e3a74227b4662ecfd6076562a3a35781e858c2312e16n/a Heodo
2020-01-17aNn5.exeexe b1c2e968bcf93056e3d058a67b3626af8edd7ccb7f2f12514dcb0514f9d5f9d6n/a Heodo
2020-01-17W4dZyW6qqIjF5uXRr.exeexe 759ec750149ade2ff4fcd6b5402cfe65eb2240a3a0d58008fb6e2b69059324e7Virustotal results 9.72% Heodo
2020-01-17RhxViKziPRoqB3.exeexe 0a26b8389b9333c1ebf76be679aa8774b933fd509d9f23a89a6d54bb554b6183Virustotal results 19.18% Heodo
2020-01-177r4vcQkZ7kVXXR.exeexe 6f684b7a05a4217fab092c075cb23752ac51b39235715de02641fbc4f6a2a0a9n/a Heodo
2020-01-179sCB0upNicKa3I.exeexe a5bd2720fe80844a82e378418655524ea646ec47bfb3a4f5e1a4df8b5397608dn/a Heodo
2020-01-17ii1PcgkQ9n.exeexe 42be66794332fb3f2578f1515d9fde883cba935409f2ab8c465809e4ea70d112Virustotal results 25.00% Heodo
2020-01-17rztnX.exeexe b068757a8bf7e90478f7ab19178308d329e5b25f8c87ac6e7f58730e5ca89a86n/a Heodo
2020-01-17x06GVE1eEGIBhZ.exeexe 7a21e9889f2c12727b85f7c710d8b50993bf7cc8cda067d4580ad16ce9a9a92bn/a Heodo
2020-01-17pL7AAHHWyJokyyxy.exeexe cf2d137e9678acd8e45134297b28aeee071411379db6c67991d7b308915baae8n/a Heodo