URLhaus Database

You are currently viewing the URLhaus database entry for http://libertyaviationusa.com/wp-content/ZB4671/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292857
URL: http://libertyaviationusa.com/wp-content/ZB4671/
URL Status:Offline
Host: libertyaviationusa.com
Date added:2020-01-20 17:36:19 UTC
Last online:2020-01-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002260291 created on 2020-01-20 17:38:14 UTC)
Takedown time:10 days, 0 hours, 43 minutes Bad (down since 2020-01-30 18:21:23 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22wgvVmmmzU.exeexe ccc82399a7ecde96a0dca013e33807797559cc4bfcbec18f6024c631d911cb62Virustotal results 9.72% Heodo
2020-01-22Zdj0A1JzYZsQMKK.exeexe 35284ec6ffa0dee09f079d172dd5d335f7e9fe1edad11f8c83889431991cb110Virustotal results 12.68% Heodo
2020-01-226JN.exeexe 42346e28a6c22408131652fffdce394439a1b87c59e66c436610a54b014a0db6Virustotal results 23.61% Heodo
2020-01-22el3S3Kh.exeexe 374da75664a5dd461b1eef87ee9de5e612c1dfabab35f9d2bf4d6aef9a73f2e4Virustotal results 19.72% Heodo
2020-01-22SwnShDDz72tyTmf.exeexe 54a83e1137df41d0ed0117d9c252bbc7269544e14e53d2546657e6c3d341bd2an/a Heodo
2020-01-22rntUWgrrghoKyAwFn7QBb.exeexe 39a68ceac062420854e9ddf48e8bfd6d5ff27bb23a1a0497b451cc55b5f097b9Virustotal results 14.08% Heodo
2020-01-227yiMoymGh3o.exeexe 4c8618caba9f10a496634515d523dc4dac4fd70e941437f79e4bb0ec80686a02Virustotal results 13.89% 
2020-01-22lzJzSE60.exeexe 4731511f5e7deec1e4ea9a006fd614f4ca30b6aedb8dd4dc3c0a076227f4f716Virustotal results 11.11% Heodo
2020-01-22mlP8d9v.exeexe fa72c919780e5cb7390758b0ea849e39977cdb2d382016392e8962a353f3c580Virustotal results 10.00% Heodo
2020-01-22t9f.exeexe 6d6cf35ac3d4ff9e9b1da3dd8eee4fc0404fc65c215bb021bd9f245bafdd756fVirustotal results 19.44% Heodo
2020-01-22nh8WvM1cW.exeexe 750d01217bf06ce255d7c673de4bf78a5fb28f8f1fefb3a2921fe782368a7a8bVirustotal results 15.07% Heodo
2020-01-22c0X90s4L3.exeexe 3d88eabb5dbd16f203843e97021ca4ee71641e9907e867966f0e06254a3c1a41Virustotal results 15.28% Heodo
2020-01-22c8tm49xSdEz53.exeexe 1d91072acadbdf007d96e3300f69321f70d0b5a211a142a12aefee1792376279n/a Heodo
2020-01-22ouo.exeexe 4dccfe82bd52ee803c380a21a18ebc9a6b5d97feaa5e14cb2042c0c0d0039ffaVirustotal results 15.94% Heodo
2020-01-220cmiJOAdlzr0Gg.exeexe 725a8a652670e41b39ad06cec3e23c57029cb8ff1fc2dc11a64130f259885da4Virustotal results 15.07% Heodo
2020-01-21sax4e.exeexe fdbed136ec7e94440efcf5266497337a713a6f4b5e12c1be52166b24dd67966aVirustotal results 14.08% Heodo
2020-01-219OaGO.exeexe 28c21e5a8d8822c96509f59fc8b6cc2fd4d70cfe8a47988f70305700455187f9Virustotal results 9.72% Heodo
2020-01-214FXfk.exeexe 2a97679165d1c550d935e46c848508b080def50eaf1157d444c0a340d5489d7bVirustotal results 5.56% Heodo
2020-01-214FXfk.exeexe 2a97679165d1c550d935e46c848508b080def50eaf1157d444c0a340d5489d7bVirustotal results 5.56% Heodo
2020-01-21fKwrJqo67g00l.exeexe 07c2df659512b6fcafc6e13e27d965bba494ec73251e74f92bd427babda75388n/a Heodo
2020-01-21OYQcjeyRp1g5hN.exeexe a30ef46b7f8eb1d853eaf61483dc4c2a156dd3bdc42fdf66adfeb6d98ba2ff06Virustotal results 7.14% Heodo
2020-01-21DTKv1Em82R.exeexe ac7a1480c93fdd2d4da3b63cec3b990b8114c0d482e9d8771b841af9567cd0cdVirustotal results 5.80% Heodo
2020-01-214av8HKj2PFRiYMH.exeexe f874b531ea8cff169cadd58ad107567c27bcfdb4c4274a67fed89c5654fa8c12Virustotal results 11.11% Heodo
2020-01-21ikujsPkAkHGNX.exeexe 2e6845cfd882440b4b1b9639e028af3e52b587643703fdb8929dafa679bc0c60Virustotal results 8.22% Heodo
2020-01-21aOV4hoS6oDLTWdifSD.exeexe 1893752e8b182b0926ef2c1e352cdde9eba3594021e447efe85a8ce563af8c66n/a Heodo
2020-01-21lhAOwb.exeexe 2b0e4b77a650da3ede432c8088c5111171bd440f8771bbc3144275d8b4dc1872Virustotal results 18.57% Heodo
2020-01-21skoLPR3OmPu.exeexe d194e8a9546bd1d00da5a0c803fb7dff445fd425d1e0a3d6ea2c06bf1ea4e462Virustotal results 15.07% Heodo
2020-01-21Y2Gce1fhDPZQ.exeexe 062edeca52238dced2adf67ee15b6a069b04b504d22204383d977eb2afd00c99Virustotal results 15.07% Heodo
2020-01-21ZsxVU2lzKAYtWHo5y9jNs.exeexe 9cfa1e48d7c2581278093d9065ecd7abe75ecd28029632535e71eb8d49088cdaVirustotal results 13.89% Heodo
2020-01-21Cf5lXWtVaa.exeexe 515a0ffcd28a2fb49e951f2c8693278424356adbf43ef4c4182c09aac98a4d8cVirustotal results 12.50% Heodo
2020-01-21Qvobiy8.exeexe 00471fd7831e2cd242bce6de313deb0ce655a14dbbfec76e49ea88d99ea7e054n/a Heodo
2020-01-21nwECfsfkRV.exeexe 200968940b46bfb149c864b8068ae150c3d8bf3b6cfa7e1afead09c3cbfbad8fVirustotal results 20.55% 
2020-01-216t6eLxCNgG8uThrk.exeexe e91988232afc64a13f1d19178a6d94c0feec41e937b425521490d80692afb6a0Virustotal results 12.50% Heodo
2020-01-210p8SYvwbdHz9LkuWwSH.exeexe b089426a5b0831f307ebdd82194cb9f98b656b0899cb2a72f2826756766aaf7eVirustotal results 13.70% Heodo
2020-01-21sx6YpHdcvCJdbumi446LM.exeexe 496283460370e32a3954d2360c2d562b9d30b3eca4ca6685003b47f7dc09e749Virustotal results 12.50% Heodo
2020-01-21U2muI4.exeexe 9155a5efd8fb200dd85081c8d15db6049dd736ddffab901765c4317b33473df3Virustotal results 11.27% Heodo
2020-01-21wMJcQmQe6RsaRcDnk1sj.exeexe 266e5cb4bdbc0543dbd8accf728734dd68f5c0554112f02e5fd8df8826121402n/a Heodo
2020-01-21ffJndpEIMo8gTT.exeexe 63c12ec84f01d38819ac2236403e0f0fed6fc8fc730fd56991cbd8a032bcc133Virustotal results 7.04% 
2020-01-20gigi0hlsbtrXwm2GUMUm.exeexe f45603b1e9f2806d97f27ba622164282d4a283b5743c2f592914d13f01b7a6bbVirustotal results 7.04% 
2020-01-20A1TOrCV.exeexe 8b3818229300847663433be28f543a5ab773bbae81f58627491e6f2eee7bc8edVirustotal results 26.76% Heodo
2020-01-20Q9PUD9QvnNI9kPha.exeexe 06253fa4660702290edc9c16fea70e348171ed82051aba5ebbc8255f400fc6e3n/a Heodo
2020-01-20XC7G.exeexe 2e342eb976a7c9ee6530249e877581bfba9175d7fc76eb383f6380e396871994Virustotal results 23.94% Heodo
2020-01-20BSPs2HUvjtd04TyQkzaYG.exeexe cb793539dff91ba5bed52d42cc2a7fd2e336be4735b0e27b11fec0357a256866Virustotal results 23.94% Heodo