URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xnautomatic.com/gij0w/uefx7f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292649
URL: http://www.xnautomatic.com/gij0w/uefx7f/
URL Status:Offline
Host: www.xnautomatic.com
Date added:2020-01-20 12:51:28 UTC
Last online:2020-02-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-20 12:52:07 UTC to mazhiqiang{at}yunify[dot]com)
Takedown time:29 days, 21 hours, 11 minutes Bad (down since 2020-02-19 10:03:26 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-074truRshHJ9KIZv.exeexe 26fba392c80731fec754055c1bc6c871f585d401b4906d5c673ee33de4c1676cVirustotal results 11.11% 
2020-02-064truRshHJ9KIZv.exeexe 8b0ae8faff9165080575cbcf9de52d7d13dd46ce204fb2ac0aa809b5a7a53c2cVirustotal results 11.11% 
2020-01-224truRshHJ9KIZv.exeexe 77f64ad0f42de2c10cdd5e9421f9090e0a7bfbe08ceb3599c543eaca4879cdb2Virustotal results 12.50% Heodo
2020-01-22k.exeexe 517578861fb7db6f1eede1668d713145f75b0d7b4c8c625829465d40d5c7eb55Virustotal results 10.94% Heodo
2020-01-22PrcnNyf33.exeexe d149e5bac45c8f7df860c13f23cdb5655a1257fe8f039d8e9868f2628331d2a9n/a Heodo
2020-01-22RE27Y7Xzq3.exeexe 1c39c570e93b3623508f42b1e4c0894dd2e1b946ac7e24255f046dc092709c01Virustotal results 11.27% Heodo
2020-01-223PSuW1wm4qVapycEPrNZ.exeexe 69f3c015ba88d15c9ea25a51b690517d1006bcf15d681491123cb2b0b9fdbf98Virustotal results 9.72% Heodo
2020-01-22JDh85ULG9.exeexe e8482377d43022b28130359f4b5a6d6a6fe536b7e0efda77948e8d2ce769fcb2Virustotal results 19.44% Heodo
2020-01-22D6VOwwt9ov7e4dE4nyQe.exeexe e702976039308260b9aa47616b09b6d574d96b23dd346a6e20e26c64b2ee04e4Virustotal results 15.28% Heodo
2020-01-22ahxx.exeexe 4d293b410a4b8fc9df89d511477178e3355a61f00cf45ea5c029793cbe307facVirustotal results 15.28% Heodo
2020-01-22V2.exeexe 9038628accaea929b5fa3234127a6d88de2535898a8dddab1ab53255487a7b3bn/a Heodo
2020-01-22epxj.exeexe d7262ed2ca3fddd2d88a0407a08023d2b6bebf74d645fed54e6973910637b394n/a Heodo
2020-01-22eZGhUDJp.exeexe 36f9dfa34d8f60ff6b00d7a36da56b41c9ceb3d0db89669856132e18097ac6bbn/a Heodo
2020-01-21ErijXwaxxc.exeexe 9adcf8f8b239fc508f1fce8419df683aa8f28053642adb2dca3098a221b0babaVirustotal results 11.11% Heodo
2020-01-21azoEYu4iMSxIlI.exeexe 9a92357495a937ddd824909d88d41eba6d01016956dd1ae8618b563329fbd13eVirustotal results 8.33% Heodo
2020-01-21XkTr.exeexe 7b378f38ef21bec1a6f9b2ca5b4bea1886c7f3c766dec11761cfc364b671a1a0n/a Heodo
2020-01-21IE0LueVl.exeexe f6f947f8729628666026d79752879690909690f6af6b23ba02c4d0cd52e440den/a Heodo
2020-01-21k6oDrmgC.exeexe c2ca5c9714e3f197430866380765dbebb404cb8b4146fe3f6938412cd82bba62Virustotal results 9.86% Heodo
2020-01-21wycKz.exeexe df64d6abca99483bb5e9effb5ae2e8bba29dae9c8f120e84283cc6e9a16611eeVirustotal results 10.96% Heodo
2020-01-21f4tG6o8Lh.exeexe b5282f02369140d96ec060b174c0c5fd922385188184ca7d01bd1fcbfa87f429Virustotal results 7.14% Heodo
2020-01-21Nppy2l5E.exeexe 4edbcea79122b38fda2e2e81e8604b8e2559b735dc46bee82d3e56e24058eb5en/a Heodo
2020-01-21R5c8Xjw0rY4CDNsGdWh6.exeexe 7c6f5a658dfb346c5950c0112ec05c8865c3250eeace599a4edfab74d97dab8cVirustotal results 8.33% Heodo
2020-01-21DjJJVttR2hZh.exeexe 4b9ed4d9791a654ad5ff4b18f87660cc04691dfd8ff0c32bf8745cdcd3934284Virustotal results 16.44% Heodo
2020-01-21eBlq2oCb9bro4b.exeexe d3969b1315a777987ec36730f731722b4f25fefcebbb97fcb8f97808a6130edan/a Heodo
2020-01-2189skYGvivWWHEpX5D.exeexe d59158da0c10e46a0943e8b5153fe84c7345c3f4ba9878933b37315e1e2aa11fVirustotal results 21.92% Heodo
2020-01-21J.exeexe a2f380ba16cad84d9826e71ea08a45c6be749e725a3ed4a276f34f6377449506n/a Heodo
2020-01-21cSktGEkHI.exeexe 013e582a650b36a85b1ed9e2ab1695f21e8c32edbcddb46fd28bbca00a9eb686Virustotal results 12.50% Heodo
2020-01-21J2FdJA37d7DWDV49K.exeexe d937b773d522a94f93f8c7203784f5ddb6458a4212815ad5ddf94a579f4f5021n/a 
2020-01-21t.exeexe 3365d8843b2521fa49195ce79f132cbf4a7e88b8885c40f6aeefd3fa42358e84n/a Heodo
2020-01-21F19JbKdZhjsv4L.exeexe bdd1e47a0024b0a54c4b95bd11bfd9dbc02efce8c17955fd428e782cb7dd8dc9Virustotal results 22.54% 
2020-01-21lS.exeexe 60998826fc127da1dff2236ea9999b08d0391603a49270f3c3f0f56cabf3dd95n/a Heodo
2020-01-21MzC.exeexe 1fb65491e89dacd90524def52d033edd3992bef136817ec1e44c67c0b495f9eaVirustotal results 12.86% Heodo
2020-01-212Ze0.exeexe 33b5eaac99469a5f52dc6885bdeb797f201552418c98801a297fe28f2d44a832n/a Heodo
2020-01-21KjGwJaFn.exeexe c1db7b979f854696a1541c78ff0d33325d24dfde940a8fab935a7caffaf1337an/a Heodo
2020-01-21ZFsdWS6er.exeexe 0a4e03ccd9b67da98c405ef0d12fcc9db4025b9abaab79a15c874718e0907d55Virustotal results 8.33% Heodo
2020-01-21dLtKWL8MDYI1mWP94v.exeexe 565935cd9bce7d68150bd932a4166d5edfb0136454993af0f1a0c8ff5d63878dVirustotal results 7.04% Heodo
2020-01-20LRH6Qbb4eVjlsPpu.exeexe 7bd342361326001abcf9a805729b5a32a131351ff6a3a98115a00c7eaa92e367n/a Heodo
2020-01-20hU132xlaq9jty01lJsK.exeexe fba188daf0cf3e5b43df577fda4707fa0896e35661fc50bfdc21b88298d90684Virustotal results 30.56% Heodo
2020-01-20fuLwYbggVIVt1TSok.exeexe 9e5f2c2c9f7cee71f4cdcb813f9810e70d9c554cdcee91c0dd5c48fa6173f303n/a Heodo
2020-01-209.exeexe a02db248bbde386c53b183ae07825fc3ac1e713f0f6712c683d901e55b638c9bn/a Heodo
2020-01-20GaaPDE.exeexe 267f1693dcecd0dc3f4972c00be87ef7b339763399fd594762fc3b9b89c0b2e9n/a Heodo
2020-01-20b9C2A2eoygVtIDPZ.exeexe 01c2cb8f30032246a313c0a10a4713c28a953766f1b4c5fb09f720750382c6d6n/a Heodo
2020-01-20Dhivu2Z0LkFF8T.exeexe d21233e4158f993f99667d107d2f41041dd88abd1e40bcfe040e9b78f48d0490Virustotal results 15.49% Heodo
2020-01-20lbtE1OzE6I.exeexe 95605d25a4ce6266bfbb88a7a349766bddf663486b9bab0ef1f1255fecd20425Virustotal results 16.44% Heodo
2020-01-20xCsUBypbmyu.exeexe 5dfb2ce217cc1fe27200843fc37e668a5c816bb43daa9945bb705aa38bf41e2bn/a Heodo
2020-01-20ykF4tDpJ4cr.exeexe d1fc1c57fb6eeea68ad3479e74aa8c2f2f306409839476a85639e8a42bc649feVirustotal results 13.89% Heodo
2020-01-2047aO.exeexe 2041129028b4e4cf851ad591fe6cc8401a61f342c58a573865096ddfb6f4c3b6n/a Heodo