URLhaus Database

You are currently viewing the URLhaus database entry for http://wemax-ks.com/wp-content/ibDhQPG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302882
URL: http://wemax-ks.com/wp-content/ibDhQPG/
URL Status:Offline
Host: wemax-ks.com
Date added:2020-01-30 13:15:14 UTC
Last online:2020-01-31 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 13:16:05 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 0 hours, 45 minutes Poor (down since 2020-01-31 14:01:44 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31bHvQRnqSq.exeexe 997c702f9ffa86ead265bfc4e55ec760218498b171b7876d55787abbab693cc3Virustotal results 18.31% Heodo
2020-01-31edHPtCpuf7pSlNmoA.exeexe f34d95c098f031069d6fc48484be088a9375426e6832ecaa34bc5da81df11098Virustotal results 27.78% Heodo
2020-01-31vnpc.exeexe 395c0613518c8decf1d178fdfc048e64c0278f11f786b23858eebd4617cea828Virustotal results 29.17% Heodo
2020-01-31B8wQgr.exeexe 27b81d6e85c56eb86c83639bfebae1dbe958de003500a011a2242c9bbb741dacVirustotal results 24.66% Heodo
2020-01-31YMETGJSDzofwvsBw5CvR5.exeexe 9b50b2ea7a48984053759eb8c006fd30fabb6e620a142c4b989e79e477263446Virustotal results 22.54% Heodo
2020-01-31k1w.exeexe 830471aa79174dc45b88dba2fe1f209c8927ff0251da09bd8ccdcff8d8978c16Virustotal results 26.39% Heodo
2020-01-31716kqq49umS8UmGn4nS.exeexe 1dc6a20c2aa10fa80d525546326aa1026bbbe6cc3e53a5a59cbae909c2a52a85Virustotal results 22.22%Heodo
2020-01-3131EqxO5xfTxEC0u.exeexe 01be74fe4d2de40dcd2c7ef5e7247e32ba5b392dfb861e52db884babaff6a5cdVirustotal results 20.83% Heodo
2020-01-31KZ12zaJtt6rDDDcSOl9.exeexe bf0a2de760ddc0327803c63e97d6c5cc628a3871aa9ff29bcfc81c43d2eed691Virustotal results 19.72% Heodo
2020-01-31lnePWH.exeexe f4295c1e1158978ff27a49809f8676d7f1f215010efecf8ec3f040c81f56d6d2Virustotal results 17.81% Heodo
2020-01-314Q6.exeexe 4bfe37cf3373329ee2927964b9155b500bc12ba31176455d10ac34a94b37aca3Virustotal results 20.55% Heodo
2020-01-31YucR1Oe6t6JFReYW.exeexe e02ffae79c8de596870f2d0e218905e1907110b5d513ccbd7053bf4a897b2515Virustotal results 18.06% Heodo
2020-01-30ydY5pTTge5zz3.exeexe 8d2e10026b099082a1d7d2899e31d7c32904aacece91596310fdbe5f1c6facc2n/a Heodo
2020-01-30OB77gf5jT5.exeexe 4c1342964f8b45059900110e9458f93535d75842859dc241c0fd02b7ec08d68en/a Heodo
2020-01-302nkaJW1KyYLx3PzqAsAn.exeexe aafeda0aef6b3fc3f2257f6bc0a68446b5dc1e71203f3c13c699be87641d5394Virustotal results 14.08% Heodo
2020-01-30Pl8YJBlNSO2.exeexe 6ef7901c8434ee338365914b432239b1a28f50ef8832cb963ef87648cb52d892n/a Heodo
2020-01-30ErRFlw.exeexe df9459cf7a97f1d59ec62d000733d7e0ab85a9b54e4257d64582de250effa498Virustotal results 12.50% 
2020-01-30DMp.exeexe 4d9eee19710ad1fee3345df72543c8e8dcea2b7543ec9c7e7ea8a506a62c5c6eVirustotal results 11.43% 
2020-01-30Gc4PqkR25az.exeexe 924c482322754b89a37a184a08f4e7effd42bc0672071aa4d8f78f2fe6901317Virustotal results 11.43% 
2020-01-305NgDpSbtb.exeexe d3ee20acd14eabfcc5f5c9a948eb2796151bed016de3356b878565f5f35236d3Virustotal results 11.11% 
2020-01-30SpVBezd5TP.exeexe b4e7e97430b31b675df1e98405c0e80fa70f11af4dbd55af7dd0eb6063d3501dVirustotal results 22.22% 
2020-01-30Iwz7xLCC.exeexe 39747120cec47967260653c6f5fb31ece21ab85eae17979e941cc44f66b3ae90n/a Heodo
2020-01-30o1ryc9GWee.exeexe a934ad7b12920ffc814cb842d07a24c68b0c1e5074ab825fa045440187ea70a5n/a