URLhaus Database

You are currently viewing the URLhaus database entry for https://ushuscleaningservice.com/cgi-bin/ATx0C415516/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290965
URL: https://ushuscleaningservice.com/cgi-bin/ATx0C415516/
URL Status:Offline
Host: ushuscleaningservice.com
Date added:2020-01-17 13:57:12 UTC
Last online:2020-01-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002253366 created on 2020-01-17 13:58:05 UTC)
Takedown time:4 days, 6 hours, 49 minutes Bad (down since 2020-01-21 20:47:56 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-186fj2mDY.exeexe ab5dc331127be64fb5120501c03de22a819a9ad88d8e17a8cc04e709900e4f6eVirustotal results 26.47%Heodo
2020-01-18s72aD6.exeexe dcb01fdf8ba270d3dd024fd60a28b21f0dba6ba8624dba1207e867a13085de7en/a Heodo
2020-01-18uZmfeqtWRVC1lW8xW4b2F.exeexe de0f60a71c5505434b479a16817972de087c96549a141e9e3686d94330f539bdn/a Heodo
2020-01-18KEjL.exeexe b74e55a8ce56d9820350ec899e3de1ceb3ddd6f213d0c90aa4a5c329add4131fVirustotal results 12.50% Heodo
2020-01-18ssiP08.exeexe 557c537aefac72854cac0ad0272868e6d1ebcacdf39c62ae3207c9cf7ce55c49Virustotal results 9.86% Heodo
2020-01-18CBbnQvmvijOzF.exeexe 82eb2e501d6897a8e0ea4dbf8afd728a9ea224b4c5430a79d85850e7d1715f71Virustotal results 9.86% Heodo
2020-01-182cW5xSm.exeexe 8a005cf6c3fe4f9cb08eea708c619dcc9c5c8ca0df93e5961b0766c2e6733f1dVirustotal results 6.15% Heodo
2020-01-18OF0.exeexe 10274ec59899011e808ab76acba60b1e3caeb34a7007da3d7257e74908a92a10Virustotal results 13.89% Heodo
2020-01-18seoBYlrXza.exeexe e685c407341b3175562635b2e2f468d8a7d53e461cc975919006a3776f709d30Virustotal results 9.72% Heodo
2020-01-17GSjl0fm5L.exeexe 0c6a5cfd8f4fedddbe98130c44c7066f8d5408be546c3e9e65c32bfa96768c12n/a Heodo
2020-01-17N1KUlb7oMhRg3.exeexe d8b68d96f79024dac5030360e7200a3c5785e06d2fe9e541483f71cded6bb76fn/a Heodo
2020-01-17fZ4.exeexe a0a2adb4aa63df59ec491842965efa9301e8fb301d2ea58ada83067719148c38Virustotal results 12.50% Heodo
2020-01-17qBcvQJ2EZmx2BUl.exeexe 57d4bad7ee623461dba1b7ce87aaf73e4e3312cf913a3151012b62b804e59672Virustotal results 12.50% Heodo
2020-01-17BDT4qsbAoeTvXgImZZ.exeexe 3a7ce179da319b9a159a62aa9fd2d9731ffef5c524365b9587e517f39b09a8a3Virustotal results 15.07% Heodo
2020-01-17vDP8uj.exeexe 2e1814e7d9a588824835e3a74227b4662ecfd6076562a3a35781e858c2312e16n/a Heodo
2020-01-17c9irF4pBFx86u0rDCA.exeexe 50733ece024fe4213ae6305c887a3b9e4488391303f61c179ef9138754d0b190Virustotal results 18.06% Heodo
2020-01-17mmLRaaH9AV79b3i7WNLK5.exeexe 759ec750149ade2ff4fcd6b5402cfe65eb2240a3a0d58008fb6e2b69059324e7Virustotal results 9.72% Heodo
2020-01-173SDx913USXiI.exeexe 62c67c8dbd995d7b151e8129ad87de49d0a75c7cd4caac758b86d45bb51dd80fn/a Heodo