URLhaus Database

You are currently viewing the URLhaus database entry for http://crimecitynews.com/wp-includes/DeHZs1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307502
URL: http://crimecitynews.com/wp-includes/DeHZs1/
URL Status:Offline
Host: crimecitynews.com
Date added:2020-02-04 06:43:05 UTC
Last online:2020-02-06 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002295162 created on 2020-02-04 06:44:04 UTC)
Takedown time:1 day, 23 hours, 21 minutes Poor (down since 2020-02-06 06:05:49 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06OntNCL2ttPPhKxhQY8.exeexe 020d2859ce97c1cd1c77ee35c2ae19d12d834d5fb4a4c888cb9df1fea0575ac8Virustotal results 20.83% Heodo
2020-02-06gxf4PORAEWHV.exeexe b54fa61850eb229f6e1597180a23b6607f8c967b0daf8656b0076fb88c365198Virustotal results 19.44% Heodo
2020-02-06OVAAVgNDcmVR8C.exeexe 287a28e80031fcd9453ad069c9ecea7a3efe34fca5edd1a36c3f6f2d38086d06Virustotal results 14.08% Heodo
2020-02-06pN6pSaEnFdv.exeexe 20e0239c5bf1bac7bd363d63d3fa4ba7227548bbaa04311f0574b7790bab0e83Virustotal results 12.86% Heodo
2020-02-06lgGLxy.exeexe 0f447b163dcbd405fcd7559a558256b466de441f9ca15ca8b8bfcaa296e8a12fVirustotal results 12.68% Heodo
2020-02-06ZPffZGozk3NczL1o3rl.exeexe 8065c30e2b3696c3c0fd301f998910f1f351af0c58baf2188e7634ae6bd98151Virustotal results 12.50% Heodo
2020-02-05Ulrylygme.exeexe 891ff873a0b4a6394848c884e5a5c320608bc640ddb84d54e283fe6ec2f91b3cn/a Heodo
2020-02-05E4HlARIIy.exeexe 481fb12203afd5ccc302bfc0db213e3d18dd6d5d3d0e85de1947fd514c922f53Virustotal results 15.49% Heodo
2020-02-059N4wbOs03HKDu.exeexe 5c71839ba71302fc57755a312c0812be987fc47020938511b7df6f34f1dcd88dn/a Heodo
2020-02-05dyZzkgVq6d9.exeexe f220c5f199db1cbcf9c94dbc963407301ceec39b79c6644aec1da7ccf2b20fe5Virustotal results 15.28% Heodo
2020-02-05Gi9y9ynDodGYrDOEO7kCE.exeexe ca67078d384154dce171953aa27ad6652a13db10e77a1744338ec562259d2856n/a Heodo
2020-02-05Iitrr3S1l.exeexe 4c600769351a71d22119f06512d1ef1b300dd34d3b67767cd868bacfcbe0808an/a Heodo
2020-02-05jVnBcdbGcxb.exeexe bc3af4ac4fc3a4fd0cec3aa28d29c6a0106ca86aa57e145ad0ac92483c4bc948n/a Heodo
2020-02-05w64JTcXJGeeO.exeexe fdeee89953335eee80e900f6b5c27123bb9eb1610014a80b2faa88f46948c472Virustotal results 23.94% Heodo
2020-02-0502WgyxUPdd1r.exeexe 3a9fccfebaccc437c135da416e56fd13e5b07818f2f579671ca0e2c3b5bb2566n/a Heodo
2020-02-05EaZnaa5i8b.exeexe 0b9600e577751568b80768d6b0806d2a349d4c6071bf2dea5f166c157b3d4c3eVirustotal results 29.17% Heodo
2020-02-05ts9dLpKdawP3.exeexe 21e135cb15205222bf231f40feae6b4d66e5b109faf656fcf580e655f45bb952Virustotal results 19.72% Heodo
2020-02-051zHVg5eyE2gTYeKWk4Zh.exeexe 96ceb4f5e54a6a24406de84555725470fa161698bb08529662309cc41a1db3c5Virustotal results 16.90% Heodo
2020-02-05wGFkqa1.exeexe 7dc43dbf02ddb5a2dfeed9d5ce34ab604fc6abe0c0eea26bbe81b5ab56060292n/a Heodo
2020-02-05eq9S.exeexe 38f7dabcea29f7f285625c0a512d734958d62c0045a631bcca149f18d84c914bn/a Heodo
2020-02-05b83.exeexe 688da46bbe7efe2db4ac3bbeb0b141c49bce7a3aad925890168a260c4a41ef29Virustotal results 24.24% Heodo
2020-02-045g5pBq7Us23j.exeexe 7013bff34c01769557afdf3e912737b120a094b08b238488ce7ef2aae90df65fn/a Heodo
2020-02-045swt5aYIJdEXwxHWDrP6W.exeexe 886c4a5e2c859b400271b30f87cbe22be9123648119f8e7ec4b62308cc0387b8Virustotal results 24.29% Heodo