URLhaus Database

You are currently viewing the URLhaus database entry for http://flatfix2u.com/backup/GFi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299776
URL: http://flatfix2u.com/backup/GFi/
URL Status:Offline
Host: flatfix2u.com
Date added:2020-01-28 10:20:20 UTC
Last online:2020-01-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 10:22:02 UTC to abuse{at}internet-webhosting[dot]com)
Takedown time:1 day, 3 hours, 6 minutes Poor (down since 2020-01-29 13:28:15 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-292xqP2.exeexe cea99aeddbdc0f71554a8f6c141942486c983c039c5cd8fe15c4a5517b887b14Virustotal results 11.27% 
2020-01-29faHhwmM.exeexe 208120e6fbc2224daa8fbbc7d558890e7fcb91f00c07c8b125d89dca7293853bVirustotal results 8.45% Heodo
2020-01-29mpimi4z8XhZAO.exeexe 63c6ecc69e81fcf34443a4bbcf33a8f3fda569ef0e9f6f2fb3d08eec24276113Virustotal results 5.56% Heodo
2020-01-29cWo3cP021Gitbupg7DyvA.exeexe 019b2e476b1e9185181f2b18beb1b30427db76c7420051ab29ec88c587c39854Virustotal results 4.23% Heodo
2020-01-29kORownFus3P4zVb5P9dce.exeexe bad78dcf2479af052f3689fe8928c8f187410f6874a8579fdbd079956e42b6f3Virustotal results 4.17% Heodo
2020-01-29NT2Pg8E.exeexe 6987054fd44e5673a7646c21cd5f039bafc2762c041418e4eb33cc6e4675b8b1Virustotal results 18.06% Heodo
2020-01-29ROOsCZB21W.exeexe 75a9f19c16fecf2228ef67b595deb3d972c1c1a48de58f58c455aaa97121f954Virustotal results 19.44% Heodo
2020-01-29ZVnLCn3xZyUjx.exeexe 5c5b9379e799c31a8ade699619d2c9da73c055629c43afb209c21e618317ff84Virustotal results 17.14% Heodo
2020-01-29y9p2P0z.exeexe 7f81a04be1b8c979a9fa1f9bc58bf45ac60f053cf95e82a92b18d88d1d0baf8fVirustotal results 15.49% Heodo
2020-01-29V8A3LvLwbUl1.exeexe 95de7051da91e994e5f8ca2471c75e918290655588d420ed640d3e39a0aa0f8bn/a Heodo
2020-01-29l6RV92P1xwVOaBZQkIw9u.exeexe 9ea414b9dde4653c2743a19c42ef6e5989d676db453ae2664b78f3566ef4f977Virustotal results 14.29% Heodo
2020-01-29iFZQZz3u.exeexe a9654ad0a440e6d969ada68d0dfbbdae66d9ae80d9b3cd642a65773aea5536c1Virustotal results 14.08% Heodo
2020-01-28U1lKotEiuQm6.exeexe 6e396812eab5e80811e49506797adf7d909d3334ae61ec7d47fb7b8a802f7b04Virustotal results 14.29% Heodo
2020-01-28GzbaVFkMgxW.exeexe 954ab9a02eff5371d5af9e3bc5660549d11fb023964829d3eac86651648af25aVirustotal results 14.29% Heodo
2020-01-2833W70.exeexe 2f78a37284ed6d647bcf29e7cb492ed1bcb2089469f76fb4126fe88adc839e7cVirustotal results 12.86% Heodo
2020-01-28PsnuNgNF4amY0aE2YLrNE.exeexe 58721404e9922755ecabd41046362e5b50d83e5e01a728272bad6f4f09c2bd1an/a Heodo
2020-01-28bBofmABf3.exeexe cd61bbd59682e296825ddc22b12b2daadfe0ac10fb18b553f60441983853465bVirustotal results 10.45% Heodo
2020-01-28TQY6MHr.exeexe 7fb4a2fc99859501b46d83fb20e5651968ab9be9a010d85817e896d93d153b86n/a Heodo
2020-01-28Ys1yDa6LFnQhrUqj7sT.exeexe d544b58a27f955e7ce826ebb6a5d8e65d6bec09456dfd08a578d0cf007ecbe84Virustotal results 7.04% Heodo
2020-01-28kxSvHHTuKbQm.exeexe 1ec7ae08b8b56deada729f05e184eac4c5f7ce22f53bcffb09b64f03ca923a07Virustotal results 19.18% Heodo
2020-01-28aOvKcxVSN46qkufjxj.exeexe 66002ce810492529049e876ed7948dd10730e3561522831495c870f84a167002Virustotal results 12.50% Heodo
2020-01-28ONezeWnTcUuXcsvQBWAc.exeexe e190a1731ffdd4f21587daa53d69be566537938697dcf86e34dfe36039b1295bn/a Heodo
2020-01-28lbWYjlLQtuHGKYFwA.exeexe 3815032863145f9ca45f1672015149b0fef7434b287953644158a88e8919a982Virustotal results 8.45% Heodo