URLhaus Database

You are currently viewing the URLhaus database entry for http://www.jalanuang.com/wp-content/wfwwwTbw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290887
URL: http://www.jalanuang.com/wp-content/wfwwwTbw/
URL Status:Offline
Host: www.jalanuang.com
Date added:2020-01-17 11:51:09 UTC
Last online:2020-01-20 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 11:52:11 UTC to intl-abuse{at}list[dot]alibaba-inc[dot]com,abuse{at}alibaba-inc[dot]com)
Takedown time:3 days, 3 hours, 40 minutes Bad (down since 2020-01-20 15:32:11 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18vc7u1v1iq71.exeexe 60d8175e0a4a6e115ed79800717cc27bd3e8d8b88af2f81823623c1b3fead089Virustotal results 23.94%Heodo
2020-01-18mxlb1ii29473.exeexe 54f54810bcea0c746a74a59d61cf8a4c67c2e10bf3cc260f68459b55a2465bffVirustotal results 18.06% Heodo
2020-01-18iome8o550.exeexe adab54b8bdcf46a8aac294fe80b2dc47c586c2f1a85ac8388fdb957718da953eVirustotal results 14.29% Heodo
2020-01-187s575qg065335599.exeexe e72c68e714d715ed7f2191d78555acd49e0bcd0f0895e9f784c2b36f70951428Virustotal results 11.27% Heodo
2020-01-18weny1vshx37.exeexe 9291e148ef2d475298d37c757423408fbe1a9126508a89d979da4d44828a8924Virustotal results 12.50% Heodo
2020-01-1844263564764.exeexe c129a416493ee30796872cfb5ba0fa3b8c01709dd380323f3c81692f68961b17Virustotal results 6.85% Heodo
2020-01-1889u72njb277745.exeexe de520cf939df3c2d6761a7cb9b5de683afafd72a9ec2269bf736022d1dd5faccVirustotal results 5.71% Heodo
2020-01-180n0rd831406.exeexe bce0fa82f5e40839e13f98c63e16c87c92320b5c4765ab0a1733369982365889Virustotal results 7.14% Heodo
2020-01-185jmu568510.exeexe 60d0f4b4178163eba916440efac25597ba8691c5746f65f26e681684866e17c2Virustotal results 8.22% Heodo
2020-01-17tc269m49632170.exeexe 3e0204cca8e5c15000994b6b2cef3c1d4774d5d0af9bd24b6f2ab89ead3320eeVirustotal results 10.96% Heodo
2020-01-17q65.exeexe 98cc042e980de69c3bc9a7e20102acf680af7eeea73ad44efad9af1dc95094afn/a Heodo
2020-01-17w5nt1y0380888.exeexe d3a3a9e5c48781d09e374301ef68fd62638857232bb056e061442893ac6e35e2n/a Heodo
2020-01-177s02714.exeexe b8a9529a73f681c8e2894e040723fd43340b2fdf0221e8ba9c63d5cd3df94ebcn/a Heodo
2020-01-17cqchktcu0265.exeexe a4d3de2b93e53bd0282d17dbcc3311af5d64501191b458c708601e8abc32b539Virustotal results 14.08% Heodo
2020-01-17pmk5kzie919241.exeexe 107abfebc4ffa112216f16744016b1c1eacb242a4cc12ae7877b0dea2b3093b6n/a Heodo
2020-01-17ip8neix5634381.exeexe 811ebe737d0254ee8b8f13a49688e52d6a1340be663973ecb9204ffdd474c3f7Virustotal results 13.89% Heodo
2020-01-175e6lo4ipo284590851.exeexe cf3104b37342852132753577c516dfe721302a602a3da36e311406a3588dd917n/a Heodo
2020-01-17rkw67.exeexe eec75477ffbad5bed61f24f710ea0401e7f1e328c62b15718e027c8410d7bd43Virustotal results 18.57% Heodo
2020-01-17t4l8g7h77627719.exeexe 365fe894dfcc11376010279add0bab196467ba3c57dbeba7a510130c8ae2b306n/a Heodo
2020-01-17l6xuhw1410061312.exeexe 577692d8bae0e5388ca639a09d0194ab857cd2ff7c43c14a1cd5d1f3ce4268ddn/a Heodo