URLhaus Database

You are currently viewing the URLhaus database entry for http://www.kongtoubi.org/wp-includes/hiLAx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294843
URL: http://www.kongtoubi.org/wp-includes/hiLAx/
URL Status:Offline
Host: www.kongtoubi.org
Date added:2020-01-22 13:32:56 UTC
Last online:2020-02-05 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-22 13:34:08 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:13 days, 20 hours, 14 minutes Bad (down since 2020-02-05 09:49:03 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24uQf1to6cOfkX.exeexe de91ace8fd908cdc9626860e1fd6bfcc611a8f2e786579f6ed32445c5c0ddcc6Virustotal results 14.08% Heodo
2020-01-24Bk5ZOP1qQK9D.exeexe 98e27fac09f717e28b502d29d9a59e12156d1dff3e173fd0f6b507e69d88b4d5Virustotal results 12.50% Heodo
2020-01-24AVGdedFu5vi5.exeexe 75e040069ea45d90235e552404b24f2da9fda20b28784cec07e2384da413a7acVirustotal results 9.72% Heodo
2020-01-24XQIC1a.exeexe 4a107012830698031e1502930f1de0f18518ebd8d602eb94908011311e2fa085Virustotal results 9.72% Heodo
2020-01-24jgGpYs3WaAhyn9NN.exeexe e88a8bc072c606f15bfe5638acd7d0bf1817e088e64669b25eed9ffcde0ec84dn/a Heodo
2020-01-24xwoWhll61yTfFyr7ocq.exeexe 5e30cb313f85bcf0e02a7d892b5544e606613d251fce5f1dd890f71c4b70b24fn/a Heodo
2020-01-24WfSuS4KBn.exeexe 245550c01a11da351630ae197bba4a168d26f1613d4c8dac3d8126f027407496Virustotal results 14.29% Heodo
2020-01-24L5XF0LNt3sVzxpy6.exeexe 64bb40b371c0c9668ae82192c4cf5adb09dad25ec0f8c844f818a66ad4d1e57bVirustotal results 12.86% Heodo
2020-01-24BDNPJEvq.exeexe 2011d56b088a52caa03eecea3351ce3c11ae8b107567cb8d9cd51a1822d41a1bVirustotal results 11.11% Heodo
2020-01-24KSnVJWggP.exeexe 1e6bd1cd56f4b084eb056bc7a4994b9fedb3e6406145dd2185e0a1cf986aad34Virustotal results 9.72% Heodo
2020-01-24IxJC.exeexe 4726527c46994cb045f1fbadecc0100b1819253436c733e40b33868f3f7ae984Virustotal results 9.72% Heodo
2020-01-24ykFzyP7awQz8L.exeexe 646dd82c5841edb48f53571228ca942f959a21e1dc2fc178549b93c22532615cVirustotal results 11.11% Heodo
2020-01-23zMSNz37HToSt4DHP4PR2.exeexe ed37a918cff242c521a87b51e08d802ce1f74ff71f163ed49e8bdcefb6d12fccVirustotal results 8.70% Heodo
2020-01-23eJLwWmnyMWFjmke.exeexe 207b472d42a154104e25287397ec705717e170a111a36035b3c94f8954fb5dadn/a Heodo
2020-01-236D6uQQaA4LduA.exeexe 7a5be6c0a6db6c0c91aedab7c8e7cdfb61241a0982ff455804db329368a6779dn/a Heodo
2020-01-23SeFJPSwqZJ.exeexe 7a74a6b85fd504ab40c006fe26334d7b4aaef84c743d19512222a0702dff1702Virustotal results 8.45% Heodo
2020-01-233YbUjAEnIsjh0l.exeexe 01507d8712e585c6103b361f0b17a73961b3100dd554a89bf9785d2b9fd184e9Virustotal results 9.72% Heodo
2020-01-23kWeZdr8.exeexe b0cff866fc123dd8d97e9c70dfeba637ee9083ae10fef971a47344bd01f4bfe2Virustotal results 8.33% Heodo
2020-01-23QdJWhWhRe.exeexe 85e3fbb2c274564eaf5e29c26c9b9e63fa72110a10c11f883d4ab4e7e73ef6d0Virustotal results 8.33% Heodo
2020-01-23aMWbFyunzlLV.exeexe 26f2cfc63ef326fa623c5ca5c1748c70bca1665a98cda42e12b2a3b9c03247ddn/a Heodo
2020-01-23nhCRq.exeexe 83716347163d8842af8d3c91b15d635506ad71407f1242bf948c5f1c1497ef4aVirustotal results 7.25% Heodo
2020-01-23bpAuGywVrpjgpf1BjTCd.exeexe ec336acb546da281b6f65e1de5ca2c153b32c6699ad7a9477764daef4bb5758cVirustotal results 7.04% Heodo
2020-01-23pexUdq.exeexe 6ae47cfb2f321753fa12f763e977dcba63bbd1780daad5ad3180ebda22c258e8n/a Heodo
2020-01-23ER0c4ddyMo2nSlYCG.exeexe 8191e198e8613863e44b6b6f11a7b799bcbfdf0d4981385838818ba4a5af678cVirustotal results 12.50% Heodo
2020-01-23hpF1KQe9uD7c.exeexe 42bf201df50b7de97bfcec960a8a2ed86e3315f28105140d7231768dcdac9f69Virustotal results 11.27% Heodo
2020-01-23vBOaOQ.exeexe ba1864815dfd004b1ca60e16a51238bd8e1075d8cca67537ee03545eb13088aaVirustotal results 15.28% Heodo
2020-01-23w5EJKk.exeexe 2628f40b54102395837c26d89ac124b28ee954073b705f81d4dd58f41f87fdfbVirustotal results 16.90% Heodo
2020-01-23yFtVGAfCuqvhASsWN.exeexe 17267f4c94a6ea67a441f34313ed0aa394465de600e694922095fcceac9ba025Virustotal results 17.14% Heodo
2020-01-23r6E.exeexe 14a07dfb3aa03a8f1df2714bd70e5fe127678689e0311116ff17a3373c5eee12Virustotal results 13.89% Heodo
2020-01-23XQd0TYkDaSwQhpvT0bf.exeexe 9808e71b8c9698ce2b92033d0d3ff7e61ace74a403b2be36f51fffd7025f6211Virustotal results 22.22% Heodo
2020-01-23bcE8.exeexe 8a0b8b9993b26cdef31577f92dcade2f3422b08c32e858c608259f48b0bdafa4Virustotal results 18.06% Heodo
2020-01-232VbY84AHDW5Ycqrwbo.exeexe af2c2aa8ec53442eee3978dae156a18b4d2015f3835b80f3a7ebc66872c42d01n/a Heodo
2020-01-232j8XMkhDu3YLCM.exeexe e2f254a6b730b5ae77afe10256e85219b38c89099e1bd0da32cefd383ae1eac3Virustotal results 12.50% Heodo
2020-01-23yv.exeexe b4b6bb885f838be7fab46e10eedd56e6324422d962f44f57db6b521bfa81e825Virustotal results 9.86% Heodo
2020-01-232a09adUWQi6bjC11bHa.exeexe a2b89349aca99e683f5a14bd58c5964028842115e1497d01e255f225945501dfVirustotal results 8.45% Heodo
2020-01-22BvdXrOy.exeexe fc8fda6bff63ea8cdf3c7e0fed41046b4b4570c50ec012cea42b51bc1e9b0758Virustotal results 8.45% Heodo
2020-01-22vtHP5TyFRSVD.exeexe efc6939db8bbb34c247915ca49c92a1e65eab1dc69f89f89933c7bb6928a4a62n/a Heodo
2020-01-22iDhpjthv2QVbms1v8.exeexe 5006e7228e0480948e4eef65736b01b1b7b453326beb65edcf371947a76b25b5Virustotal results 12.50% Heodo
2020-01-22bfyo2.exeexe 73975ba71279c59f926d43b022ec695cffd1e777024ec9893a9c42ebfed3e80cn/a Heodo
2020-01-22SfUoKVnTKmTZk.exeexe f02f4e90748bd3755c5f9586bea51010748894fd41a7662d969f118dd7b67ec3n/a Heodo
2020-01-22NzdF.exeexe d4760eb755f89812b7448b6eb1cb7cc03cf5d9f18981eb3e82fcff8128bae7dcVirustotal results 12.50% Heodo
2020-01-22eEbQOt8x6K23iqy.exeexe 981ded76f1845a62790716c4f38aa730559eb03a1a7dc385b3eb585662a6725bn/aHeodo
2020-01-22hMBh.exeexe 5336d54699c5f21886c781439f09251b6c2cfc6f88f7c25a8ef3bcfea62ccb79Virustotal results 22.54% Heodo
2020-01-22zgz.exeexe d45b94ebd758c9656242d3fcf9c0ded2a4b951f178488c05afdc12c990287fd0n/a Heodo
2020-01-22HOgef.exeexe d7b5f98e6a288f5687e390b0d7b51baf761c06df5e9140bd8f90fcde2c5ee42dVirustotal results 15.28% Heodo