URLhaus Database

You are currently viewing the URLhaus database entry for http://saangberg.com/wp-includes/u_a_vn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421905
URL: http://saangberg.com/wp-includes/u_a_vn/
URL Status:Offline
Host: saangberg.com
Date added:2020-07-30 11:02:12 UTC
Last online:2020-07-31 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 11:04:02 UTC to abuse{at}dimenoc[dot]com)
Takedown time:1 day, 11 hours, 2 minutes Poor (down since 2020-07-31 22:06:58 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31y9bfGTFg7CN.exeexe b5f5584de4f4a7c5234fed7fbd81b108e93cd538b33cfc2db7c95956ac47d784n/a Heodo
2020-07-31GqswOIx.exeexe 490b46bda0dba498c6431c69f60a07c8ca231ee9e8a2b03961777742789dafben/a Heodo
2020-07-31stRTBrcw1rruOl5p.exeexe 26f9ccbb643b52c67a62c12125b924d4ada4bf9c24a724cb6ce70110f2425295n/a Heodo
2020-07-31YsxwgEAsIvPN94zYC.exeexe 622b8303df95456f8fcd9c85412e2a2062bdb53c734c3947b35a370aa9b3df08n/a Heodo
2020-07-31k5mBnBQTNaarCiuJ32.exeexe d0fee2d9262b169934a4a45102f3009c1610b5f6167dfd30360e3469e22afc18n/a Heodo
2020-07-31nTF291A.exeexe 27c25cbee83b08d7d8973f210a9d278bee0b988b978a28ff627d26f35d354160n/a Heodo
2020-07-31KdbF.exeexe 8c1abc0ac5af466ac7c36441d0a48ec60e723ed6cdc77dfbd596e1afc50f8c9bn/a Heodo
2020-07-31Gagt.exeexe 98f5d8d6d1ac5928ba4200c60d1be43a36598ff04edbbf0e330c5e2b60f8c29dn/a Heodo
2020-07-31J71.exeexe 364dee528fbb50af828709f246db22b715bd3f1586454eb45ec4dd2c28a079dbn/a Heodo
2020-07-31Vw1MYGpHszzRfHAN.exeexe 346c6db1c61aaa7b10f607d0d2d92ec6bea8a27e527745a1f3e449d2a28f8affn/a Heodo
2020-07-31QeiREVU42bge.exeexe 587aaf943372197bbc9e78d5590c3942672ab9a86f744fd84447bf8a62f661cbn/a Heodo
2020-07-317ay3zN.exeexe a7e2e30e1b7c4e45974628dd23654f73775df30c216dbd85d52f268db31dfb18n/a Heodo
2020-07-31tHBedzgP22hn8LGSLRYJ.exeexe 72055f34e901c08e742eae91ee97b0944a4f4d695d127cda96f0abe1db04b2a1n/a Heodo
2020-07-31LrOqh.exeexe 6b7504e1ca3788d5e784066c769ea8c9dd822d2a53722c02890d645d4d0b24f5n/a Heodo
2020-07-31WppgIdTcIlfI.exeexe 41c28310ea0a3c6c9474516349a5f889ab024d877ca61b138decb00b2cdeecfdn/a Heodo
2020-07-31MQMlL5.exeexe 95e50663c6ad7754c86ba44550bf63391b3b5c6c4a898c6caf646a57d7fa15d4n/a Heodo
2020-07-31oSzk3HOpQoThh8.exeexe 8589aa3c8fe424a6d5b1acc4274cdea03e6732cd677ce9794e91157afb2b893cn/a Heodo
2020-07-31VrQvgFXdtgS.exeexe 7004a1d97d937d604d532fc73aa9c22b9ed3e361192cb3467136e881dfa1ded2n/a Heodo
2020-07-31PSpeRRv9zz0vsTeZAn.exeexe 5f6ca10c74020b70c3242b4e13c6d883441d34cdbb15544698a33db57eb1fb5bn/a Heodo
2020-07-31bD.exeexe 7241b127fe2e93c4a91cbe5df9eebadbca046ac0279951ee19333496999520ddn/a 
2020-07-315xB0JlaF.exeexe 58f25dfe7a3dbf0e696ba6d1096ef1f2870a527a963b4783fc126c348acf11aan/a Heodo
2020-07-31zGYhT31.exeexe c185503318222745db1303a9162e28c08add9affba39ef8929a989d1a423bec3n/a Heodo
2020-07-314l.exeexe edc0a57c1c567ba375297f935ee5574faab3fc031564ced21229e0351601c481n/a Heodo
2020-07-31G.exeexe 324cd6b23a148e0d871fd4e4b60c43082d98f5847a0497b6c164d85ae68551d1n/a Heodo
2020-07-31k4J3C.exeexe 8e95bdd7b5f05982b4e803ff7da76161eff6e93cc42ba0638ff85f679b25e7fan/a Heodo
2020-07-31KHP.exeexe 30e18bfc579f2c6c5a90f3bc3372a5c8a6eb500b1819b25f1db3885ba0d3e956n/a Heodo
2020-07-31QZ.exeexe bac78d6ce6d7fbc33c090e4bf1bf5b5783790e4f3287d231e24e052cc5db57b9n/a Heodo
2020-07-31f9aUQHl5cinAxWJ.exeexe 1832f483bcc3156d5b5094980f954e499bf4b37101dd9d2852b8d7f663e7b520n/a Heodo
2020-07-31VODpNAjm2zzF9N.exeexe b17d57f24838a7362f94dc3b0337f57c6759755bc868067a99d6235d0814be08n/a Heodo
2020-07-31WCv3.exeexe 4461bd615c89559533017e50cda0ce644bb51ed1984d378dd56c05427e4aca37n/a Heodo
2020-07-312h6SIG3tA.exeexe aebca0c50b06eb4e1bf8dc561cab62f78c8c3d5b875247b5f68faf91d226b571n/a Heodo
2020-07-312ZZ8.exeexe 51c84399d903fe435215fe11fe035d3e78687ef1b1b4e1b84571f204488d2d6cn/a Heodo
2020-07-319Q2rXPEU.exeexe dd23a24c781f874220e5ca802d92dc9111010ece1d65c86572a502ab428f85a5n/a Heodo
2020-07-31EdV.exeexe 5d0594cedb81ce7851fb366acbc2e498c2ed871f6f2d286ba07c9be2c77455acn/a Heodo
2020-07-31orCwIow522U.exeexe 612fcedfb218aab579043b8431e6aa0584480baf26a56d3d7e8d72d1d1900f2an/a Heodo
2020-07-31BFjXPF.exeexe c6608cc2a5fb4895dce9f8def90ba1f4dd05c578a58fbeb424299c55653ae6bbn/a Heodo
2020-07-31vVg5bh.exeexe de8ebb2b5fc65b72aa93d6e006fedc55955bf912d06febaeda5018fe7e95ef4bn/a Heodo
2020-07-31siAHLLf3QiiV.exeexe fccd691a06184ab3cca361064a6b4332c20b53d0017cb269fd5bc4af30034589n/a Heodo
2020-07-31UC.exeexe 3645bea65f7cb3fa583379334cb197da110eb66367eeac7a342b777d065843a9n/a Heodo
2020-07-31RTA4cq.exeexe 965667c26fdbe6b94337893c02932260046e3a196c4c19129d7b6bb0c488b74cn/a 
2020-07-31G.exeexe 919afb42a71c20f3858dd813e06c4afa513af40d9fa8c32b0b30d0f8c58ad5a4n/a Heodo
2020-07-31VgvNyYdR0Jiz.exeexe 4703129a3ae6c06b8a03ddf659c67cfe747a9ce2f4e4c000bd4ccd58700703f6n/a Heodo
2020-07-314Mpez1Mviaq.exeexe e002d8b0a3245dda907f60363e1783d77812da9f99e38aa51655f85c786c5032n/a Heodo
2020-07-31SaZOlw3llHe.exeexe f77e2fafaf641d4dada655e22858ad9508e170677da848945bd91ca37defa41bn/a Heodo
2020-07-31BWu9hz.exeexe 74deda29f8521c8d3f41b6f8aceb23c86ed892402aa7072ae521c9dc98036c1an/a Heodo
2020-07-31YvTM5A.exeexe 1d7a6bb404380fd8080a7e46e5122ea15f76824e1f865c5137e342ca05b22c85n/a Heodo
2020-07-312ce45TO3cqO.exeexe 3c94b7bb762e8a97b60510742004e0b93486d3d600b8c1a6069ee059405bac75n/a Heodo
2020-07-31Cn3pJ4JP01HXmwP.exeexe c21f130773e864b08c7dc617e315835ca1118933317df11c8dc13b5adae4150eVirustotal results 14.29% Heodo
2020-07-30orLjnGHBvRYtf7s.exeexe 46a07f8329978e15b84ec5cdc700d452f776e0b02b10ef7d3800bd53557ac39en/a Heodo
2020-07-30TTqumJ8oZze6t.exeexe 1dce13e5c7b489b2ce47ff7a918646e822fa304fc3ed9d5b7f252022a5c7a16cVirustotal results 14.08% Heodo
2020-07-30Oo1uxyeR.exeexe 0b1756c998a3ba7a0de734d70b99a7b178f092d593beedd48b0db1ee244b1b1bn/a Heodo
2020-07-30LxAizKeXpW1Qb.exeexe 279dfbafcc6c692a756e16a6b139ebe01a65ebd531a1d2e0c4fb4123093291a1n/a Heodo
2020-07-30OH8Vc16TnRRUrUUy6M.exeexe f810001c15911cdc7bbac3459fd80161338d59ad58d3498e583a034d2c8899d0Virustotal results 10.00% Heodo
2020-07-30QLPWlJpo.exeexe bca80b7dab27b70eb8ae1da1b7e9a8be32bbab0a3968b98e4a7cb71ddafdee3bn/a Heodo
2020-07-30lvzHqPHiFw5VG.exeexe 91d3ac5b6f091b5a2ce926244467c243401e9495311fc8939d6b9de4ab117d91n/a Heodo
2020-07-303sapqg5SeAnKpwB2bmE3.exeexe 646a6b7c2bad29d1ec17a2a5f8c3451ea53c2863fa9755f4bb2c72384b4bbb1en/a Heodo
2020-07-30KGfhS1R56UZk9Ws.exeexe 443ae6984d0e0d55d2cfe7f2c15726cf7abf88b1cb23e598c8c16431fad9b6c9n/a Heodo
2020-07-30xPgPDzr05UQ36mVbZ5g.exeexe 02a284f016f3f804a9a70552b27db6c1cb9d5bccae224197529a8c9c783f1ca8n/a Heodo
2020-07-30Opxx0AFhURcMycCj.exeexe 9b619761d594753156e55072e948f20b00da15a360d5cc5647f313cd68333529n/a Heodo
2020-07-30qnLe14rxx4c9d1MDlpEE.exeexe a2a3fc9163c7d2c8d912cf4d49be49a370a7198ac7738cad8bbae54ff927c68cn/a Heodo
2020-07-30NaUf.exeexe 66b4fec291d55e81c3a3b8bc37c655e55d6319df903566dcc70d598befe0809bn/a Heodo
2020-07-30sz3SuOfl.exeexe 96bd0fd8a8bdead6fcd4dfe00ad09d672cf9a22b22d6b04683b31592397ed984n/a Heodo
2020-07-30Ku1cU1dTakgED1X5x.exeexe 377e4fd716feaf56a629d3244c0bee9270c513aa56c654bec007b574ef938a66n/a Heodo
2020-07-30bNvaIQ2JdVKAs3TNH5.exeexe ec1b3d5eaea3c7e9a69adb98bb200121ca5f4fb2e47e853be9ecd7691fcd8dffn/a Heodo
2020-07-30KSt00Y2Vx4cKpzzCBKJ.exeexe 278467224c46ab80145aae6a81c0c7ad026ba67c934c200bf6fdf763da0c38a8n/a Heodo
2020-07-30Z.exeexe eb64405cffc49644b72a401f9a74404213aac8f8dc283f4bf47780831865b058n/a Heodo
2020-07-30S.exeexe 58b0231d0abcb04c6d0850183f4797be63dce1125e7bc917f113e2b53833a301n/a Heodo
2020-07-30pKFHq.exeexe 4182faedc32a7fd6b9af9afa966c035070e302797bf92424da62fff70e79659bn/a Heodo
2020-07-30fv8GSk9.exeexe 4af0db1296b897433e24622c3d1c8673baf33af7d94e90a7ae446f20e513873dn/a Heodo
2020-07-30RR8.exeexe c6047154d6ae05c6874e7b729753308e7cc6af4966a0a10d9fcfb68ec1be75a9Virustotal results 17.14% Heodo
2020-07-30HhFEEB.exeexe 7dd39138836971367455cb6931421bf256453f562ce625cd8d1fb8f4c44ec509Virustotal results 15.71% Heodo
2020-07-30kY.exeexe 39ba5df6d5b953d12adb9207edb8eac5ae79d5e84603d2c1cebed9d72e866c50n/a Heodo
2020-07-302nCmgm.exeexe 100f28d12fa252476e5f98657d77a17539cf6409af5ade3f9a04ac0e16a75c0cn/a Heodo
2020-07-304jRC.exeexe 2652941a65d4ad626b01824cfb5a9ffd9eb909654577f14bfd6ea118ed573219n/a Heodo
2020-07-30r65W1.exeexe 94072d85d869fedec937351c58e5f2495c946a8cbee1b01d41f3e00abfa6dff1n/a Heodo