URLhaus Database

You are currently viewing the URLhaus database entry for http://alexbase.com/plugins/gqwgr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294210
URL: http://alexbase.com/plugins/gqwgr/
URL Status:Offline
Host: alexbase.com
Date added:2020-01-21 22:58:14 UTC
Last online:2020-05-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 23:00:05 UTC to abuse{at}sprinthost[dot]ru)
Takedown time:3 months, 23 days, 17 hours, 25 minutes Bad (down since 2020-05-14 16:25:34 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-113dwxKDhJD.exeexe 6561354b12356ab0ca409087e2957dc341e5a9540612802a492533e222e433a3n/a 
2020-01-223dwxKDhJD.exeexe 981ded76f1845a62790716c4f38aa730559eb03a1a7dc385b3eb585662a6725bn/aHeodo
2020-01-22YifJBOw3Bqz9L9dbivwJ.exeexe 5336d54699c5f21886c781439f09251b6c2cfc6f88f7c25a8ef3bcfea62ccb79Virustotal results 22.54% Heodo
2020-01-22BJRnFawaNkT47eW.exeexe 69d5add7e6f88e2824e61ec5db03ad9f4aa16142a3a8e03024a07838a9bab408Virustotal results 26.39% Heodo
2020-01-22WFSPbA8lU0Y1SmD.exeexe f0f1cf8874dcd7bd4935b79479a20acc1d56ac1acf8f01e88da472ac488f4c3eVirustotal results 15.28% Heodo
2020-01-22LZPtGxiB1Yhw.exeexe 3bc2879e374f29d71519edbb8ff71e22148c9dffc058e6b4f8f635cf9997be0dVirustotal results 11.27% Heodo
2020-01-22PKygTbKVcFNPE5d7.exeexe 517578861fb7db6f1eede1668d713145f75b0d7b4c8c625829465d40d5c7eb55n/a Heodo
2020-01-22xRsAIKCXj3.exeexe bc14b5fa88a0aa8ccd1de5e957bc0dc13162832fd2e84610b7e5e915e9eebad1n/a Heodo
2020-01-22ZcNfY2voF3DiD.exeexe c126859368a0fe751b21ec121b4e06b83910721751ca3cc64d2801345c03aa91n/a Heodo
2020-01-221z71VeMgg.exeexe 5c0edf979334478cbdfc30f2d9185c7259da53bb191f47c68cc1eeda91d59ce6Virustotal results 9.59% Heodo
2020-01-22hrSARjZ419G8KFxUyqB.exeexe e8482377d43022b28130359f4b5a6d6a6fe536b7e0efda77948e8d2ce769fcb2Virustotal results 19.44% Heodo
2020-01-22SLmgEl.exeexe e702976039308260b9aa47616b09b6d574d96b23dd346a6e20e26c64b2ee04e4n/a Heodo
2020-01-22g.exeexe b54aa451ca7548b6a6251fef2294afe7c5e98a10b35e32b65fd2c94e4c646b6cn/a Heodo
2020-01-22t.exeexe 9038628accaea929b5fa3234127a6d88de2535898a8dddab1ab53255487a7b3bn/a Heodo
2020-01-22Kzm.exeexe d7262ed2ca3fddd2d88a0407a08023d2b6bebf74d645fed54e6973910637b394n/a Heodo
2020-01-22fWMXCm.exeexe 36f9dfa34d8f60ff6b00d7a36da56b41c9ceb3d0db89669856132e18097ac6bbn/a Heodo
2020-01-211WYH.exeexe 9adcf8f8b239fc508f1fce8419df683aa8f28053642adb2dca3098a221b0babaVirustotal results 11.11% Heodo
2020-01-21x8M92391.exeexe 9a92357495a937ddd824909d88d41eba6d01016956dd1ae8618b563329fbd13eVirustotal results 8.33% Heodo