URLhaus Database

You are currently viewing the URLhaus database entry for http://bjbus.net/files/9O85/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420376
URL: http://bjbus.net/files/9O85/
URL Status:Offline
Host: bjbus.net
Date added:2020-07-28 05:32:28 UTC
Last online:2020-07-28 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 05:34:05 UTC to abuse{at}eboundhost[dot]com)
Takedown time:6 hours, 56 minutes Good (down since 2020-07-28 12:30:09 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28ohc3NsyDUPA.exeexe ee4d667d4862bbea359709bb27892f3b6cbbbfcc62386c9a1ff19f3257e2aeben/a Heodo
2020-07-28FuRhN3mzat8zstXHK.exeexe 6be9276f76f1d38923382095b85229c21d8906c064973acd9bf2adee79c14e85n/a Heodo
2020-07-28FuRhN3mzat8zstXHK.exeexe 6be9276f76f1d38923382095b85229c21d8906c064973acd9bf2adee79c14e85n/a Heodo
2020-07-28iQJzz6VUJf7qr.exeexe 9e643311b9ce0daecac99606997e972a721c528c7158c83bee54c5d43392fc8dn/a Heodo
2020-07-280ta.exeexe 593b8efec2ed3f5622eac23140a7c217bf7faffb07a98c091ee50c5e74fb6544n/a Heodo
2020-07-28FP0fwaaQEiT34h95.exeexe 77d8e39b7341673183639a1ac3ff7b9f3c9cf779de1f4ccb7110567b1af7c1c9n/aHeodo
2020-07-28QLDG.exeexe f6f94a5b44ababde6d0ff9c955d04bbd456eae1eefb37bc9b3d9b82e8639d29bVirustotal results 19.44% Heodo
2020-07-28FbI9Wn0jfpxAoqkic7j6.exeexe 0f05cb63ba00e9bcafcff93b4866ca31f1d3395be0ebda0a69b98510914dae86n/aHeodo
2020-07-28xZHcqXWTxZvCvXLZI.exeexe 79fcebf033291995b71b2696b965c631c3264098ccab23dfa725ad98e5ed5cbdn/aHeodo
2020-07-287iDLPWnx.exeexe f49701c7e96b1d9fadb5aeac75a9ac07f3750057bccb86e8826a33bd689a1eean/a Heodo
2020-07-28KzCUz44VgIrNlpKop.exeexe 1c2aaa529e32769d99b71a54fb3148e5c7a8b70f3c1a0de550df4f959309ab80n/a Heodo
2020-07-28Tx3b.exeexe 5b3b0b1d9c67f5a8d5185c0bb7585c3ea0c6905085c9082ee1a616b2ebc9d9f8Virustotal results 11.27%Heodo
2020-07-28TwEFO7Rdky.exeexe c21932972d11c7983d3fb58336ade9843de82df517d25f61a0602d8b0ce2923dn/aHeodo
2020-07-28r44Je2z0ObOBEj70bLvBE.exeexe f4d263c6de0508e3942a7636411d88637549705bb773866b4f699c0b55e84088Virustotal results 23.61% Heodo
2020-07-28d2QqC05ar3dJLAASOr.exeexe 1629c18a3c0b7056be86fd3ff3911abc0db5083eedcb52f4c327186f3ccf4980n/a Heodo