URLhaus Database

You are currently viewing the URLhaus database entry for http://www.yuzemin.com/wp-admin/2dWf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:296248
URL: http://www.yuzemin.com/wp-admin/2dWf/
URL Status:Offline
Host: www.yuzemin.com
Date added:2020-01-23 18:50:12 UTC
Last online:2020-02-15 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-23 18:52:07 UTC to esabuse{at}hkbnes[dot]net)
Takedown time:22 days, 10 hours, 52 minutes Bad (down since 2020-02-15 05:44:20 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25SiqGuAXIMGF5y.exeexe b757f658232b6812c7672194b847ca33d7e4a6ba167fe4a14aa83d4c3fad034bVirustotal results 27.78% Heodo
2020-01-24YlgIgrhsi9y.exeexe ecd361b66034c850c308817754f984e93bcff831ed0605cf3bfb457a05471e0bVirustotal results 18.31% Heodo
2020-01-24uMmYkY5Sz4TPFBTWALC.exeexe 64c6906143bdf4b6bc3b35778febf9e98bd48a84388fe76d71cfe1630a2e0025n/a 
2020-01-24h5xz.exeexe 452470d9ac2b3f2a41282a145cd3f550d754fe2069dcd45b0b8cb11ff3471219Virustotal results 11.27% 
2020-01-24NHQCa5CuhMmmGGsgnW5nk.exeexe 6d01b134ab439368ac170ba48e4f708f6d460e8c5e3f9c30d513a2d1d540a5f9n/a Heodo
2020-01-247CHBaSuxa9VAPbHX.exeexe a631692d354d1da38720467b331c1bbafc3eb42e675e2e823c9de2899425a69aVirustotal results 11.27% Heodo
2020-01-24CvrgjL33.exeexe c53933bc17b3eeba5f84e11c6b272d3f04b6c259f745f9634f08beab34482be4Virustotal results 15.28% Heodo
2020-01-24ltuoPC7M3tvbve9.exeexe 4409177a13ce486cfd27a41ed5915516902a800d3d22172bf513c5eca545454fVirustotal results 11.27% Heodo
2020-01-243GqpWKykPZTxN5mWZwkBq.exeexe 2b8c98b714ee871a1f2c4e0e09646f03434bf1c3782cd2f2283f2b2aa487976cn/a Heodo
2020-01-241MMDD3F8YOht0.exeexe 7b466af5dba03442ba718d7cb296f7a87a341505fc3afac840725b766137f83cVirustotal results 21.13% Heodo
2020-01-24MOtvBPcEzhjdnqWc6.exeexe bb27530fd2eff827bbd99295c97a5fde54fab140d4e254dbb77cdd800925c8dcVirustotal results 11.59% Heodo
2020-01-24HbaMUwY.exeexe 27aa662b8d6e64835c58833396623a46c82b3f1294838ae1da5927f049febf74Virustotal results 11.11% Heodo
2020-01-23yzfXbRrXnQ.exeexe 2e85130bd9c914274285e473f5f67d0139ee071315a172fb9a49160be1cd5338Virustotal results 9.72% Heodo
2020-01-2377Jl.exeexe 9e7593b471f571af39c50febab4c92c8d30704cb65153023fb8ae2b88c96ed17n/a Heodo
2020-01-23lbU.exeexe 21d0c5f286bbebcc8b098304e4d05756b0a707083175027e8389dc66519cc46fn/a Heodo