URLhaus Database

You are currently viewing the URLhaus database entry for https://ir.aihgroup.net/wp-content/Cya8Ku8je/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303992
URL: https://ir.aihgroup.net/wp-content/Cya8Ku8je/
URL Status:Offline
Host: ir.aihgroup.net
Date added:2020-01-31 12:53:24 UTC
Last online:2020-02-28 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 12:54:14 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:27 days, 15 hours, 7 minutes Bad (down since 2020-02-28 04:01:57 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01CM9.exeexe e208f36c523f344b81474e05991070cd906e7f49b9031b9bcd2c8e7c117d4914Virustotal results 40.85% Heodo
2020-02-01A5zmHH6j2AWeOQF3O2RlN.exeexe 7d9c030e44f4b97776d5609eb991f8c5030fa2e66e6380d44ca724097931acf7n/a Heodo
2020-02-01e694sJmKRy0.exeexe 41be72948b364a145bea2060f8911e755a83136cd15d4496dd0c186b6028d44eVirustotal results 37.50% Heodo
2020-02-01a4hdkVba.exeexe 4a13c0bb6583680635dffd16255c1006ff72f716cb90fbd1fdc31ca1414b4637Virustotal results 35.62% Heodo
2020-02-01l8Be.exeexe 7470c9f580e58ab46fd40c9cb741be7d0ae27f13045c8355da53f4b104e9e27bn/a Heodo
2020-02-01bRFbJAiuV7z.exeexe 85083f132ebc1a351285198235698ba199f8d94f288623ce22f4ee500424b594Virustotal results 31.88% Heodo
2020-02-01hIa3mScDXVh.exeexe c4962cbc3fdf9287c70f2481a5250a7911bfecd361730ffee204b6bdb0066388Virustotal results 28.77% Heodo
2020-02-01ur2tu7U2XaWvFvoohqY.exeexe 696476d0a174f3bdbb32b84478e62379f76b878ca9641376c88a21200010d621Virustotal results 18.06% Heodo
2020-02-01Yckg3qZqx3CdtJ99.exeexe dbe27ec53fbc98efce705b7b1736208aac4c9dea5d991511dce48102db3c36c1Virustotal results 15.28% Heodo
2020-02-01sZZqqWd.exeexe 3c6be818ccf1de59ec69557aa8667ba385db357a8ef8a20ae3e1fa369994e678Virustotal results 14.29% Heodo
2020-02-01xd9Up779uLkJSCwdoETtz.exeexe 8fcafc142255b1498bf5f3734656711996a586a51591a9dfa6dd2a3cb13f79b8Virustotal results 16.67% Heodo
2020-02-012ZLLhXa.exeexe b91e640b9712048aac4ede7a25d5b5442c95d11fc73c116894dc030ea87657bdVirustotal results 13.89% Heodo
2020-01-31RF7dLXPe.exeexe c5a76793c28a38a0434d84025d340df5b63100313e9915bebd58722f8fa07067Virustotal results 12.50% Heodo
2020-01-31D3kQ.exeexe 02e1d3d9b835636671fd20fe4092657eae1b358f4fb962b5d4edfb8e113df1fbn/a Heodo
2020-01-315CVfs.exeexe 6c1781806e34330a4e2c89a89904245ff04382ec536ec2cfd67c22ea74b3fd7en/a Heodo
2020-01-31jGWkDEtPA279nxp1Jl.exeexe 219d34229248f46137b1abcd7b75399824b8af86ed4022de12345fa7b20d5b8fn/a Heodo
2020-01-31WrnXHRI0SEsP4.exeexe 93685a5abf8ca5f8d33f343a68c32ac1c4ec2d25e920f017f9837d2b323be424n/a Heodo
2020-01-31vZEjwgNolUpk95.exeexe 536223343bfcfaacfec0d3498f57758786a53c6b208726db1524999559d0e1dan/a Heodo
2020-01-31NaJ11n8Mtcpz.exeexe 63a0934eba09a9a6726dc3b73ba4d04d1657b2728dd760739d9c65503e57bc8fn/a Heodo
2020-01-3151ylaHPXkG.exeexe 3a8f1e5929dd0572478da9576af351a6dcbf0c8eb21cb2fdb0d007b355e6542en/a Heodo
2020-01-31ysP2mcw.exeexe 5bdf911168999f9dab58df8bdf9fb3a871aeda296f98e76389f8f51a4e235ffcVirustotal results 13.89% Heodo
2020-01-31ddVWK6jYWgDCdtKV.exeexe 678ad34b66037d0cc68e34b6f254dad9f754c80e6a1dc8f07b2794464667ee28n/a Heodo
2020-01-314rgTIZB.exeexe 997c702f9ffa86ead265bfc4e55ec760218498b171b7876d55787abbab693cc3n/a Heodo