URLhaus Database

You are currently viewing the URLhaus database entry for http://ayumiya.co.jp/Engrish/swfu/d/default/QG which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36740
URL: http://ayumiya.co.jp/Engrish/swfu/d/default/QG
URL Status:Offline
Host: ayumiya.co.jp
Date added:2018-07-30 13:09:20 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-30 13:18:25 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Tags:emotet link epoch2 heodo link payload

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-31216438.exeexe 04bbd72b1b29b28439c54e8c66bfea3675958ba2467f75d0f09ef384a358474fVirustotal results 18.18% 
2018-07-3189329388.exeexe 10810ac39fa23e7e64330b95724cd649040729705b9fbeba03064fb81ab6346aVirustotal results 20.90% Heodo
2018-07-3139001.exeexe e0295b10fb3dd50e67a54d05ebd20e6b5367d47c5e4baf3cacddb24845fd570bVirustotal results 29.41% Heodo
2018-07-3156561.exeexe 7abe546ff1089a46af506eb67658e8ae9871afaa26439d52b96b820469ceff95n/a 
2018-07-317833.exeexe 0c084cc2de37b46cb6ed667079d9cb675adc83f7b8f9ff0d94389459b2d6b7d6Virustotal results 26.47% Heodo
2018-07-3171742.exeexe d16655a476f9b67dfe70545e34c4bf72ab07b1d357e627e25bea0bf0c14ba3ceVirustotal results 26.47% Heodo
2018-07-31032.exeexe d12462606ecfa64d74e725bf830d63b941fcab09da43d7c7cfca18dae77f8a93Virustotal results 26.47% Heodo
2018-07-319003353.exeexe ad943cab4f5dfb8c4378f46c54ee83ae4a1010a065faf496e47880975d636abaVirustotal results 26.47% Heodo
2018-07-3103.exeexe 38b76b88cb3d785295d26c9ab7083e91ad4813d56f71110ad34c85670242b7a9Virustotal results 22.73% 
2018-07-3070.exeexe 097bea64ad5a8accaa8e493cb77c90b9a1f2a747f94e20cec898cc1f8a075d59Virustotal results 22.06% Heodo
2018-07-303893897.exeexe 092451b48f7b9093925d309355bbbfb8d81ee6c6c0986729f3749fde9a5ad7a8Virustotal results 29.41% Heodo
2018-07-3067203.exeexe d0635947dc4ab4dbd49dd2f27c8b3c3e6db197d23a1d19f4c4b4e174cc8b6500Virustotal results 20.00% Heodo
2018-07-30275135.exeexe 4eea743665c289df6a55b72cfdf2fcfb283b9a8e6c855a64cc28bdc72c4acf6cVirustotal results 19.40% Heodo
2018-07-30274445.exeexe e44caa3d342dc8f9964af2b0731a799e2248f469c6445021ea51a62dd740354dVirustotal results 19.40% Heodo
2018-07-3057145.exeexe cb0d3962464b17bbb491c6cdbc806f27b56757e18857918838962528c045a3a8Virustotal results 17.91% Heodo
2018-07-305086.exeexe 042d559dc68086dc9c214f554b2a9bc29833b9b252594d00f6c5ca9f41aae3acVirustotal results 29.85% Heodo