URLhaus Database

You are currently viewing the URLhaus database entry for http://witje.be/awstats/lseZLdJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420292
URL: http://witje.be/awstats/lseZLdJ/
URL Status:Offline
Host: witje.be
Date added:2020-07-28 00:22:35 UTC
Last online:2020-07-28 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 00:24:02 UTC to abuse{at}axc[dot]eu)
Takedown time:9 hours, 13 minutes Good (down since 2020-07-28 09:37:08 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28dij4xn0k979784719.exeexe 3a3632a730fa7ae06d6d39ee50b28ed89d5e175b60bce36c278f7141c9f545f1n/a Heodo
2020-07-28t2jr6g5567233.exeexe a7cb18255fda13f5241e6e7456d88bd5c17564053296b35bb58af29f2295ad27n/a Heodo
2020-07-28t0m74z7xxc17.exeexe 74a9de8a5b2d021055ac323485639e92519f54ee0860b2557a8cb38b8fd27cden/a Heodo
2020-07-28jepd339613525633.exeexe 7c58632a85f448ec59e846f86257122c16a47ce73495a0259832abd06d1b20f6n/aHeodo
2020-07-28d91zh57943554.exeexe 4bebc442878ed5cf8a9790e5990711c4147758288a0fe9ede3b1efd847ede6e8n/a Heodo
2020-07-28m1ghgia0427769602.exeexe 2c669e816ac761ed5c1613f409141144a8a62c1c95f5c8ba0f3a6efb5e1b4855n/a Heodo
2020-07-28v6ujdgc20953849.exeexe 158c77874cc0d66e1d23ff75de12c9861b14307d45a3ee85237702699b01a57fVirustotal results 23.94% Heodo
2020-07-28hs8kk9c5wr364488.exeexe 6d5a5bf9db86e9b08598ce82c456cdb969724222e6e9215c1e19826d62482099n/a Heodo
2020-07-28ijzwjq12pj6494.exeexe e9d3da6c62781db498280ade4336a24e435b87aaff9c7f76907249375fa76a52n/a Heodo
2020-07-28eqp8a9txh99371831.exeexe 102ca696c4291e583e825ef4fa87c7e781c5264e5c4550133195cb0cf319f392n/a Heodo
2020-07-28uf796311.exeexe 99dd7d2d697145f8d3d6ec385af3723d004d5a04062c997f56e4345f636f8190Virustotal results 22.54% Heodo
2020-07-28x94oxf673449508.exeexe ec4f85d47ce5b2194f6a554da987288ecef50a0685631d97475abfa636e2ea4fn/a Heodo
2020-07-28y8y76.exeexe 7a5e1742918863f2f754a018cb2ad1ff9339b3eb8868375f7db98dcc43a4982en/a Heodo
2020-07-289yqxh58f87.exeexe 3dc6e22502bd8e14016c3abeea226d09bee25cdbea7623009cf386344d1c747an/a Heodo
2020-07-28nmxtbq275992.exeexe 6f652406a9e982e32fca081f72e0af16ceb3ee365ed88cc064c42bdeb87b955cn/a Heodo
2020-07-28uhu925.exeexe d360d5930e243f7dbab43e3b0c58cb5a75f254eea4beee687f583b1e52cc2b2bn/a Heodo
2020-07-28c1c62.exeexe 7501d8676d94c7922fa9b0738375651602616982b5b31cef2e21b1fa5e5f5892Virustotal results 15.71% Heodo
2020-07-28jjkddvg927880.exeexe bc63bbfa11dfdbc266cee373e84ed58a062de4245db4fea8f5918c29e4aaee7en/a Heodo
2020-07-28wf0d5er132013.exeexe 6980f8595aa742c269e287c0720e9dd0e87a35045857e9ebd1bce3b0c38996d1n/a Heodo
2020-07-28v45lxy211.exeexe d043da056fe9883070c5df433f1b6b9278305c7b679308f42449fbb45018dfbdn/a Heodo
2020-07-28rmbkq8lx887.exeexe 2b248fdc842a76ab7cf00fd06837241dd6b22c1f6593f4d609d796456808fd19n/a Heodo
2020-07-28fixq4404520245.exeexe a0f7c826295110668ced57a497677b3719fa7c84d2be0deebe92af0daf70801dn/a Heodo
2020-07-28hzkv5224.exeexe 3773ffd238bdb60b2ba2280446268421dd1d10ce7c3bf4dd4d369c2761e4aa06n/a Heodo
2020-07-28l9ys777676223.exeexe f0ed327c862cdbe0fe2f055eef1c6202b2806199a96d11c9481434a72d5aa3d1n/a Heodo
2020-07-28i03b366.exeexe 3e9a6845b7a716f3c231a64e14b2cffb3ed71f552f73afc928515d257902d87cn/a Heodo
2020-07-28at758812.exeexe 246382dd78f17239cb7fe6cab1e72f70f953d11d14a4073346ff8173bdca7409n/a Heodo