URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xnautomatic.com/gij0w/dxr-fqb-008/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294971
URL: http://www.xnautomatic.com/gij0w/dxr-fqb-008/
URL Status:Offline
Host: www.xnautomatic.com
Date added:2020-01-22 15:32:41 UTC
Last online:2020-02-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2020-01-22 15:34:10 UTC to mazhiqiang{at}yunify[dot]com)
Takedown time:27 days, 18 hours, 29 minutes Bad (down since 2020-02-19 10:03:15 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06jz8.exeexe f817a6b223bfde2cc33ca36d13bbb32d57d73f5c889db5ebe1793bdd083b1b6fVirustotal results 6.94% 
2020-01-24jz8.exeexe f825123d184df9fc3a9bae7f5dea8462b6915746d623d902b6ad5e52fa96be53Virustotal results 11.11% 
2020-01-24w9osi44.exeexe ab459aeb7e2acbbdc92a28500ec7234d91682e97b1288c091b9dadd52505f380Virustotal results 9.72% 
2020-01-24kas51ue2y9416227.exeexe ac52a0c8b093182fd5c8cb062b71f28bf6c952536443b36de92eb1316d8932abVirustotal results 15.49% Heodo
2020-01-24pu596161807.exeexe c2ed1e5a4c9bf4b5fabbe397982dbf2bb6136ec30f6fc028b2399cd00a9ff8d1Virustotal results 14.08% Heodo
2020-01-2434d60663254.exeexe 0e25c75a97af044f142acf094fe150e806d94ceaf2cd1119b932df1b9fc6bdefVirustotal results 11.11% Heodo
2020-01-244kql6goa00711650083.exeexe e192061d600e8f6ced2d48c26b32af2fcfa18cb97f564bc1d3d71e7456a4ee09Virustotal results 11.11% Heodo
2020-01-24j9w8ue86480391220.exeexe 7a0cc4f218bfa0095364430a194dbf830c1f51801343bce436deab0783a197b5Virustotal results 14.29% Heodo
2020-01-24niambb270414.exeexe b134523478f20656574bca96ddc2924520ca9785d9cab8b6b15f872d3a10b389Virustotal results 12.50% Heodo
2020-01-24x7na29.exeexe bbed4cbcd570d202c7168aa298791e8e832d6d077c494278f88fdeba494f2d65Virustotal results 18.31% Heodo
2020-01-24gvwxsiv1a359.exeexe f2de10b51f4e7cffabf659fbcec529c5b3f0ed8f48625e1b37180e76a1aa466eVirustotal results 13.89% Heodo
2020-01-24ju78441449.exeexe e6d61a3bd74627bff83f92c4518c264fff6eb1d1f42c732835c37c3af6015b09Virustotal results 12.68% Heodo
2020-01-24b9y4sovs3287462.exeexe 4de0745dd2884414dfd5384ea1c773a4644751d90a873361399de98d7a6d8958n/a Heodo
2020-01-24xuwrz773.exeexe 9871ef0139be5623f9a580a385a18f7b58428407c9867536db8ce375034c1277Virustotal results 11.11% Heodo
2020-01-248nweiik7ih957.exeexe 6c83890b19cddca0fb68f988d7c669c57cae4628252c6685cf70fc876cc6f255Virustotal results 12.68% Heodo
2020-01-23ckqxkakb472849367.exeexe c253fc144fcb7ce7842381015537252adfbc80b5af583e17206d55e54c8c69f0n/a Heodo
2020-01-23plo4sf5074040078.exeexe c17b52a1fa5c66bc509e0def3fbdad1d5f2082a740eb727e45423ac69ff63cc8n/a Heodo
2020-01-23yjku63v1wf589.exeexe b1a113c6d70cfc58cf40b4facfa93e909eb7219c4265b2294c1c9f63e06377d2Virustotal results 8.33% Heodo
2020-01-23wimevp0mc20252.exeexe cdaf24694cbe6c4b0464228a19d456afc49b5535bcd6d9805d99da9b221b02eeVirustotal results 12.50% Heodo
2020-01-23jkcugih1s6475229783.exeexe ec09ac3ebc4f08670d33554162a7119c150504892d150873b9c85ceda952deefn/a Heodo
2020-01-23zyi9p5114816800.exeexe a6d4cd67be9a74dffa41ff5a319883ebc6d3c0aedf1ac2810785e114e5270953Virustotal results 18.57% Heodo
2020-01-23qelk029004.exeexe 66df4a289f6b88f81d2d34386341ebf4012525bb1280e52b3cb0e0583b516410Virustotal results 9.86% Heodo
2020-01-235e69.exeexe dcd52666549489f076804e67acbc3ade801e245c4f94a8b229772109d9b9fa55Virustotal results 8.33% Heodo
2020-01-23ru6dj82.exeexe f5631042a3bbf8fac13a7c56d9cec6c0190fc5e858f89eeeebba84d1deaaeac0n/a Heodo
2020-01-23gzhncp8w6489.exeexe 22eee98f509f24084137c26a2336cd10fca55d0964f67145b98ea93b923d4b40Virustotal results 7.25% Heodo
2020-01-236lj3apd9j0567515.exeexe e142ab09dc6021c9ff0409bae2adcdeccf7d96f9b0d79396b9921650a084cb0dVirustotal results 14.08% Heodo
2020-01-23hl319357527.exeexe 7ae91f32cdca7d854d19439bcff58e2707cfa3cabe1483a16892464dddd3adfeVirustotal results 12.68% Heodo
2020-01-23ye1bj0415058.exeexe 83a9e359dc4322c75bbced3b9d9c254089f1afe739f31b7fcf8641b2e25eea3dn/a Heodo
2020-01-23gsl4.exeexe 5fc2e928851d6c7dfa044450291a49b44add7fde0101bd372771ec65cd384b2dVirustotal results 15.49% Heodo
2020-01-234ds4.exeexe 29eac70c84e19b37ba04fa6f67f5dd177bd42956baf399573db11bcbd817d2e7n/a Heodo
2020-01-23kwzz5768409666.exeexe 01d1e9cd7a00b5005308558f14ae6b27f452840238ce3f4589f9f99c9c143f5bVirustotal results 19.72% Heodo
2020-01-23bm5326.exeexe 0189037f4d398799e88abfbc8c2721bb9a749c4cf655bfe4a429dbaaa8ff1eb0n/a Heodo
2020-01-23m89g83055.exeexe b6f2283951ad3704839d81f4712bdce0e3bc8ee6d2e93c3dab9d8d0976f6622bVirustotal results 20.83% Heodo
2020-01-23rqi6.exeexe c344dbdffad5a8a65d076dd7576c4d676ba15e94702b6b8969b148217dbceb5an/a Heodo
2020-01-23sdrhyxey24250351.exeexe 7f9f9ad54683cfac6df8d51d095bc0b762f55404fa72a208e538ecc27ee8a968Virustotal results 12.68% Heodo
2020-01-23n75342168388.exeexe c6a669bd011f41ca3a232b7227b1e1185bd312a88b07308849ca63852e5f3c1cVirustotal results 11.11% Heodo
2020-01-23x1n42364.exeexe a181697d4bd677882c89c2846d73d933fcad7d0155b1dec9d39da60539d83cbcVirustotal results 8.33% Heodo
2020-01-238qzl05apf4666254.exeexe 731ccc35d35caed665a73e0a053ca03010239982dfbdf84b44d5d622d92dc028Virustotal results 9.23% Heodo
2020-01-22yjxkp4550767.exeexe 43b518227ebbfa6eb0e867315cd8ac6ab92db9f522c67fcc9abc1b688a5db14dVirustotal results 11.11% Heodo
2020-01-22ds9jn421221.exeexe eaa16efcb17c901e25feebd1589baaac7c16a11da24cc0d01885ec590ce0c911Virustotal results 12.50% Heodo
2020-01-22fmqzjy9137796449.exeexe 80fc0617f2d846571ec3b3e5de540621ab02a494300d4ae17a03bed54c102b2cVirustotal results 12.50% Heodo
2020-01-22xpj1th4264752573.exeexe 16c8d42770d6a7937c69b5c45f0df037e6a15f9e812c2143e6daa3925ff1840bVirustotal results 11.27% Heodo
2020-01-22x2lvan639053.exeexe 3bbe7bae6378b40205842cfb01f80e65003de826e2bd98a41805164d30f481c5n/a Heodo
2020-01-22vwne2d2cn737544856.exeexe 211afeb4add87635edcf39c359cd8df51e3fd54ac97ad7cff75f1bd1d549c0b6n/a Heodo
2020-01-2280uv9e57680587.exeexe ace59c27ebb05c1ccaa4ee588adc94d7ac31dabf477b0af8ae540b2e34fb8ac9n/a Heodo
2020-01-22e715157768.exeexe e7bd1a79c06b3896ddd971d17d69a7655891b1f6550fb1ca5534f4e65902e227Virustotal results 8.45% Heodo