URLhaus Database

You are currently viewing the URLhaus database entry for https://koddata.com/wp-content/GP075/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:304294
URL: https://koddata.com/wp-content/GP075/
URL Status:Offline
Host: koddata.com
Date added:2020-01-31 20:02:16 UTC
Last online:2020-02-05 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 20:04:05 UTC to abuse{at}ihs[dot]com[dot]tr)
Takedown time:4 days, 20 hours, 33 minutes Bad (down since 2020-02-05 16:37:24 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01HrGObQVm63Y5sPpBp6.exeexe f725c1a5bd9d480b97e5e2f81840c7a4486ab2498f1d58feaac55fd49ff7c2f7Virustotal results 37.50% Heodo
2020-02-01LhUbBVAZGPnNnjCFIUiEH.exeexe 3bc65f4a2c57b8479c9aed89075bb655a799226642af0354017f03492c25729aVirustotal results 36.11% Heodo
2020-02-013GyYUZIx9c9vcvZ.exeexe ef1bbb77238c870dd15f98800db41fc0473deeac50c959314819ff91cc2ddf69Virustotal results 36.11% Heodo
2020-02-01GSrm4Qe.exeexe 30cd0a8dea3ff9bbc2b0ad0f6813d4c626936bcd5b964ab542692903a9b2faa5Virustotal results 23.61% Heodo
2020-02-01VMR2Ls1HzI7t0bbBW.exeexe 696476d0a174f3bdbb32b84478e62379f76b878ca9641376c88a21200010d621Virustotal results 18.06% Heodo
2020-02-01NsMPyxZT0YHk6YMFGGPK.exeexe dbe27ec53fbc98efce705b7b1736208aac4c9dea5d991511dce48102db3c36c1Virustotal results 15.28% Heodo
2020-01-31j0dHDSDvopEjv4um2Z7lM.exeexe 4ece933ad29034eb9ea762bc7ac11102ab442a74451003abdc8f024e9ce63bc4Virustotal results 11.43% Heodo
2020-01-31Trpvkm887n.exeexe 8131d8b1ecffc520d3332c6aadfbc9a5a0f7dabaa40864c58bcab5e606fea50aVirustotal results 20.55% Heodo
2020-01-31BYs3crKfB5Sa001.exeexe 5872726a58fad2d3f3eb038faf6f6380f014fa022d9c8d81207344163dc95934Virustotal results 20.55% Heodo