URLhaus Database

You are currently viewing the URLhaus database entry for https://sparkcreativeworks.com/spark/QoZqtWjUs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422016
URL: https://sparkcreativeworks.com/spark/QoZqtWjUs/
URL Status:Offline
Host: sparkcreativeworks.com
Date added:2020-07-30 14:58:07 UTC
Last online:2020-07-30 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 15:00:08 UTC to abuse{at}hostwinds[dot]com)
Takedown time:4 hours, 26 minutes Good (down since 2020-07-30 19:26:13 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30fmrxcu6a3.exeexe 6b7528c9cc4201d02106385c9b80d5f98c607db8be629dd88889b75a7c187708n/a Heodo
2020-07-3079cbuwa0544592.exeexe 10ed2c43ebfa8e2320d6a90274f38528b164151bf699911ce826cc3dcabbddb2n/a Heodo
2020-07-30il1faa0u0557027509.exeexe 3aaee966915e8bf2dbdd53c054819a6a59312d7073f64b098f689fc17c42e89fn/a Heodo
2020-07-308r4191.exeexe a3e943fe37977334f9640c4f40fc18188fc740eeb6c3e2fc56a5f3d982297ff7n/a Heodo
2020-07-30debd0.exeexe 57217f41c239aa93c51e57c43bc35bf08914f402f2dab7b024124895b0782fcdn/a Heodo
2020-07-30zrxr1vig9048.exeexe b71389c0f1531c7cff57e85ec189afc53422a18de693ed8fce68025706bca724n/a Heodo
2020-07-30odud45822.exeexe 3ebb2b0c3a0c8b46ec982ea0482ac604b4ce9de629b6237b93a584b9cd4c98f5n/a Heodo