URLhaus Database

You are currently viewing the URLhaus database entry for http://adventuremania.com/oicqfb/Uzuf1449/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303991
URL: http://adventuremania.com/oicqfb/Uzuf1449/
URL Status:Offline
Host: adventuremania.com
Date added:2020-01-31 12:53:11 UTC
Last online:2020-01-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002289211 created on 2020-01-31 12:54:10 UTC)
Takedown time:8 hours, 12 minutes Good (down since 2020-01-31 21:06:51 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31xD88cfntUOl39uccSB.exeexe 3a6f8643490f9a912684d77f4a40cfc210dec901f7a7f7830be53e7540e35bd6Virustotal results 19.44% Heodo
2020-01-31kZDXI.exeexe 2be248ec9e3d343a95f5f141f4e1ed7b059eeb09c252de521f3977a914824a0dn/a Heodo
2020-01-31Q7DeS6wAqm.exeexe 317570d6205a3c483b22954863714f218415d535981d4acbcc007105380e7038n/a 
2020-01-317L4qDYtw1iA.exeexe 3a8f1e5929dd0572478da9576af351a6dcbf0c8eb21cb2fdb0d007b355e6542en/a Heodo
2020-01-31DCRYclKVcYpH.exeexe 5bdf911168999f9dab58df8bdf9fb3a871aeda296f98e76389f8f51a4e235ffcVirustotal results 13.89% Heodo
2020-01-311Ds7fW.exeexe 678ad34b66037d0cc68e34b6f254dad9f754c80e6a1dc8f07b2794464667ee28n/a Heodo
2020-01-31r9o7BbahA8ZJ.exeexe dd13d54ee85f31187a6440f21db51ef80df868939d6c9bd542b2cd3ba27e7340n/a Heodo