URLhaus Database

You are currently viewing the URLhaus database entry for http://etawala.com/BACKUP/egNICnA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421736
URL: http://etawala.com/BACKUP/egNICnA/
URL Status:Offline
Host: etawala.com
Date added:2020-07-30 00:45:30 UTC
Last online:2020-07-31 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 00:46:05 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 17 hours, 14 minutes Poor (down since 2020-07-31 18:00:15 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31gf02.exeexe 03d40e6a8c28886ed229fe29030de83d593aafe2eb62a4f8fd9b593e8af0eaaen/a Heodo
2020-07-31uier08313265.exeexe a59fdef0605248a3d778aedd02ad647097228728d9d5af217107e082e8f54445n/a Heodo
2020-07-31xp28d284539.exeexe 3389c831da07d8ff64fd5606d2c0e696eebd463bbf5b75c99ad7cac0e559bd51n/a Heodo
2020-07-31b167tji6369.exeexe 40b27fc8fefc9ee359e65f9f14647c17f4f723f080e0123354f63d5cfc20d469n/a Heodo
2020-07-31zcgy485.exeexe 6039f245c156db7edd4b009b60b0f945b7b1441377a558a7438bceeccb6cc8d4n/a Heodo
2020-07-31xlekp3592327606.exeexe 0bf755f0897e82d62b69f4ee330e2f7a25e1dc158c978a93656fe3ddfc3722a3Virustotal results 10.14% Heodo
2020-07-31cypum6.exeexe 2338dd8d682631eb60c7645e781c2a60155447b679bfa724667650d7780d36edn/a Heodo
2020-07-31ifk879.exeexe 980e2029956aae284012be23c76e89d1441d6c14836a04aec8e57f0b5d4a36cen/a Heodo
2020-07-312xd960.exeexe aad68215da58059e6c30e25e948af0ef0969c7154eafe6aca9d78ee522a079dcn/a Heodo
2020-07-31nwtyujlh8204009.exeexe f6a415bdcefa7a718a5cfeb5786bdda5c955127dd2d482ad7ab8c5be42b1007an/a Heodo
2020-07-31pl7.exeexe aaf5b6671c99f60989706b03c192946089d088985aafd57955fe6baf17e09a48n/a Heodo
2020-07-31w91lclc85793361.exeexe 8e01e7d6cbef1c4eb282186f7eee2b7bf3eec5704f0367f919070f59eafe8aeen/a Heodo
2020-07-31zx9h7275.exeexe 4410ac0a2b9a36df0ad4c6067f11c2991bfe07c04e59865be2f03572fe184822n/a Heodo
2020-07-319bxe4h7565614.exeexe 711c1a95379826ab762a09dd109f1823e85a7d96b3b37462e55512269af8479eVirustotal results 11.59% Heodo
2020-07-31yy6egcf0p176360255.exeexe 89c26fc72e9a2492ea1849a2ba9774a6ff94b07a0c29c88c9d70b86a637a926en/a Heodo
2020-07-31rkg84454515.exeexe 297732c5eecea7e1969649e9b52fe86f593af7021976e93b527182ffd8f4c2e2n/a Heodo
2020-07-31pba0yt797208268.exeexe 419906660e1af498b4a4ef08f37a81733cb40111709863d0fa038ca13190206bn/a Heodo
2020-07-31e1l982132528.exeexe f2f644cbd1ad363c5e21d8e81c0ecd707974da34b44eba2eceb81544312509e9n/a Heodo
2020-07-31swo0c053141334.exeexe 946def85da03a85bfd3aa42b39ce6893b9c41e7d33f0f65e435dfb694561fa51n/a Heodo
2020-07-317zbe13i2.exeexe dad62b7a9287355a3199a72ad2d360ed46f11c6a881ed4d0f4ea653d2393d57dn/a Heodo
2020-07-31d8oq980674604.exeexe d78718b814a407b19b1cc1d0a21223e94ca83dae6f662efdbc06d7468510025fn/a Heodo
2020-07-312efufpjato83376675.exeexe 6a254975cff92bda4e662010dbcafaf20ce40ca9c96bcf85c9a93a8bb09d9ad0n/a Heodo
2020-07-31ry285908816.exeexe bd1d95aee19ee09f7b79f6157ec4fce0ae1896c209060a12bf2d12039918083en/a Heodo
2020-07-310ge94z1402.exeexe ce328920740a4c019608eb9276937e7f54ea026dd491149e947a897edd3f30ffn/a Heodo
2020-07-31aglsdm87546.exeexe 56b225f9eace385f22bef1e0ef3d99bc49267ca539d36e337cdef0782985522bn/a Heodo
2020-07-31x27ob5297.exeexe 3c94573b6657095bfba441db53bf85fb1114779b2863ef089ec18550ca936bd4Virustotal results 20.00% Heodo
2020-07-31jts738.exeexe c4c95873c5cb8693ff5c518f77692a6a3d6cad9594418ff63401b0b4ccef6edbn/a Heodo
2020-07-31s0qfa6gdd109.exeexe 04db547add3236adc8308512ba11b4238c99c7e5b2bacc81fa4279a91007fa87n/a Heodo
2020-07-3108n707.exeexe 4add112b27567f6968a568af031fea1a89b51e6403d8901d76242be18c2c5257n/a Heodo
2020-07-31ms24bkft305542060.exeexe 80e0adf4262981175d1b261c1390ed9581dafaeb09379a5fc456c3600893ea07n/a Heodo
2020-07-31732665856379.exeexe a86b93c6cdd4915ef092807edf050930992878b3ad8a9d0a341becb43ad3859cVirustotal results 18.31% Heodo
2020-07-311ar49eq849250.exeexe 20627e9a3e7595d6ce91d6794c5a2370d6acd516b04e40e0ce362f09b198c0a0n/a Heodo
2020-07-31d7f9nlu898.exeexe 1bdee3a51a7773e32c5ac325864ddfbc051298524140ac6d64ba4708381b0267n/a Heodo
2020-07-318vxto6l6.exeexe 7ecd0421f935394fc47b5b6f9783fb1b00a183f153ff9b91bdcf43dae9f23b7eVirustotal results 15.71% Heodo
2020-07-30upl1tsezf163745078.exeexe 8e9863cf0274e7aa8cbcda59673ac5b29bd3e6167a4e21be9b6c1e22f33230a5n/a Heodo
2020-07-30gqksylbg877132.exeexe df9376c2c985e4325208fe0f99553f453f51bee5d938de307eaf9380ef61dda5n/a Heodo
2020-07-30zajj844234.exeexe ccf2c012ef94114d035c924f085a583ef8eea8435f3cb79351468715f7b7c0fdn/a Heodo
2020-07-30oex3186.exeexe 8dc4061980e02f49a23b5b833bca3ca23debc1437a1c365bcc49142a6f7cdc6dn/a Heodo
2020-07-30d0t137.exeexe a74d2709acff6af58db65d8fe134f547c9567501652ef93daa1e402a18cb2672n/a Heodo
2020-07-302a640.exeexe eb65d4330e00c84b7f80b208054ff6c5d0ca2c30499df7da6a1761fed77af758n/a Heodo
2020-07-308nj2t692407.exeexe 06a87125ca65389497e3d2e5a207c5f5f37592d1265257a7fd26518e81e16885n/a Heodo
2020-07-30vas15767477.exeexe 1526586debde024f3ec060f21a406bfa484f082002f1b5bbacdec511c386a607n/a Heodo