URLhaus Database

You are currently viewing the URLhaus database entry for http://duketownschoolcalabar.com/css/on6681g3k-ivb0jr9-83/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295978
URL: http://duketownschoolcalabar.com/css/on6681g3k-ivb0jr9-83/
URL Status:Offline
Host: duketownschoolcalabar.com
Date added:2020-01-23 14:52:31 UTC
Last online:2020-02-01 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-23 14:54:13 UTC to abuse{at}24shells[dot]net)
Takedown time:8 days, 20 hours, 27 minutes Bad (down since 2020-02-01 11:21:16 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25q9b8n0898984.exeexe 1ee70b016a82ac9664f6248e04f9a4b7830c83012cb1d1f4bc153b004557c83fVirustotal results 26.39% Heodo
2020-01-25hel1a5dspq533.exeexe 138115ff24468b89bcee7b095808432fdf082af1a6d27b954b3c576cd7574215n/a Heodo
2020-01-25jykfam635767729.exeexe bcb5c0f41d867565038f2bf101c3e4da4a2fbee560d00f2fa53503c0ac30cbf9Virustotal results 22.22% Heodo
2020-01-24dp57838506.exeexe baae63e9111825cc0f911eee823b8de3e38ccd0f38bf8876fc43d13ebe70b87eVirustotal results 19.44% Heodo
2020-01-24ar6.exeexe 649b7bb7d764e9f1902b4ea62ac3ad06d22c4d1d53dc38d4cee1105d1513fbe8Virustotal results 23.61% Heodo
2020-01-245s6qk93u6659174.exeexe 30c97b3e27c161e72a43184b431c3cd1ae853e4eea75aaed06717a92d001863fVirustotal results 19.72% Heodo
2020-01-24jmco0gnaeb8.exeexe 598ea767a1346bd785b4a8eef6a8057d50c52dd4f76b2d9083e75c1a328fcc06n/a Heodo
2020-01-24kmk22.exeexe 4423aef8d0221409e95968c6e99e1987ba344393b011417b7469f348eec98cf2Virustotal results 9.72% 
2020-01-24cfvffq429.exeexe 2f73215e20af793f79d1e5b4c70f72edf98cba8513bf07969fefaa4c3a1e2baeVirustotal results 12.50% 
2020-01-248cmsvm99685.exeexe f5ab9798583d7f76ee8c9e2839435d85a4da1c6a960c4a6c5f1b2b9844a09e8bVirustotal results 12.33% 
2020-01-24c47.exeexe bf4975dfa997ce8bf9a3ea347147268c89fc6146dd03946a5b486114d27c775dn/a 
2020-01-24zml4j69349944.exeexe 0c6d4bfcfd6fd8081c972fd2e3126a7822e0373578c632f097dda28101f5280dVirustotal results 9.59% 
2020-01-24xsxv569880756.exeexe f825123d184df9fc3a9bae7f5dea8462b6915746d623d902b6ad5e52fa96be53Virustotal results 11.11% 
2020-01-24k7azogmqaz055.exeexe 5a94a2276675b79e6c052cc4bdae2f030cd0e1834595b718281437b4faafad60n/a Heodo
2020-01-2422qz7.exeexe c2ed1e5a4c9bf4b5fabbe397982dbf2bb6136ec30f6fc028b2399cd00a9ff8d1Virustotal results 14.08% Heodo
2020-01-2404r93637.exeexe ff26882f564b641d6346126263dddb4fab59d73a17183f5973d6d391b2228512n/a Heodo
2020-01-24dtc7l445404.exeexe a9bad6761f3f9fc73637910642c8aee62e84abac3e24475ca2e67b32e18af081n/a Heodo
2020-01-24scnwvjxq849.exeexe 4e5e4a0ea8c9fa964efd9cb922567b20e02a4a96e019a5cf1ed2353957bd61f8Virustotal results 13.89% Heodo
2020-01-24bv29g777045.exeexe f347b28cea8707d20b36aa535f3723523b26167d7204d4cfdb89c6e4c0c42e5dVirustotal results 12.50% Heodo
2020-01-24e2mq03.exeexe d5dee8c717edbfe8da0f9d970c4f19e27aeb75085f71c49dadff6353dbf29ed7n/a Heodo
2020-01-24watu9k7.exeexe f2de10b51f4e7cffabf659fbcec529c5b3f0ed8f48625e1b37180e76a1aa466eVirustotal results 13.89% Heodo
2020-01-24o0f4dc721351739.exeexe e6d61a3bd74627bff83f92c4518c264fff6eb1d1f42c732835c37c3af6015b09Virustotal results 12.68% Heodo
2020-01-24tpspn74wk54.exeexe 4de0745dd2884414dfd5384ea1c773a4644751d90a873361399de98d7a6d8958Virustotal results 11.27% Heodo
2020-01-24romgc246.exeexe 41c85b4b21996495e32cb6243df47db777fd0c04721c3cf3b3eb8c303fe59b8dn/a Heodo
2020-01-24ky617677852.exeexe 7fd6380485f36ba84827c3526075e3225bc71d597f0ece30b6ffe10a936db762n/a Heodo
2020-01-23e09sxypp1b5691479.exeexe 9ed384d813e8ff1c65dce21d521f603ae725d8e6d6e92df784c3517bb9ec378dn/a Heodo
2020-01-2395dogyg0d1216.exeexe c17b52a1fa5c66bc509e0def3fbdad1d5f2082a740eb727e45423ac69ff63cc8n/a Heodo
2020-01-23vfykky54.exeexe e8bf23da389f2e171857fd14ddb43627bd63ee6ee481dbe8438e606b9b009fabVirustotal results 9.72% Heodo
2020-01-236liq421538272.exeexe 2dacefeea97514e7b70a1b8d910d38c5020c7588841c200940316a2ffe1ea21aVirustotal results 6.94% Heodo
2020-01-239i099801407.exeexe 178ba8a2cae706525b189fa54c1d7f599295c1e7c3cc48d1c11e34b574cdb1d5Virustotal results 7.04% Heodo
2020-01-23l35a051709463.exeexe 4837ea0006aaac86618a76408795d30dd186b34981efdffeb82942616e944150n/a Heodo
2020-01-23bv33qk928.exeexe 66df4a289f6b88f81d2d34386341ebf4012525bb1280e52b3cb0e0583b516410n/a Heodo
2020-01-23di7op4fotp7947.exeexe 1baeabcea067d55dcd1404385a2641a77e66be0789d368ca52bf6b712e888921n/a Heodo
2020-01-23rrvu29375.exeexe a33f009d32d97b8f1c4c1f780163c4d8ef648d143dae80dd60b15968d4bae78en/a Heodo
2020-01-23ry8cblr448.exeexe eba62aff729136d4cac398249ad93be0629d653852268b16a75f3620537a4f50Virustotal results 6.85% Heodo