URLhaus Database

You are currently viewing the URLhaus database entry for http://smashingcake.com/blog/HNpury/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422835
URL: http://smashingcake.com/blog/HNpury/
URL Status:Offline
Host: smashingcake.com
Date added:2020-07-31 13:22:17 UTC
Last online:2020-08-28 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-31 13:24:07 UTC to abuse{at}quadranet[dot]com)
Takedown time:28 days, 2 hours, 43 minutes Bad (down since 2020-08-28 16:07:52 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11zyd687.exeexe 0560ad2aef939ce41af718a555a6eff00a6b70b3a6e88309a90f305d8781c2e5n/a Heodo
2020-07-314bd4.exeexe 6bb9d04224ed78c9925405b2d6fb546fad5cbc67eeac7632e1d8fc1d02763affn/a Heodo
2020-07-31xeekjyz94117.exeexe ef5a92ba005f4bf28c3792a9de84845bf28fe4dd61f2fdec7aed58ce77001f0aVirustotal results 13.04% Heodo
2020-07-31fioa815310.exeexe 92096cb6bab392f75789ed1cdaf2f489139de9dc89a782fd135566509ccab225n/a Heodo
2020-07-31ilt1vbc0a00466.exeexe d11ffabe729e9f2b216e5dc7c554736ed8a279aee885f21f2771cd06afc08c51n/a Heodo
2020-07-31bl2kby0498406.exeexe 8f7df70663f97385ba9cb979ee2ee8c1dbe8064935c614a13beeeab796a26343n/a Heodo
2020-07-31d603.exeexe e42205049f473fe4d80e65d8cb11c362cd79dddf27d6cf45e19ea157a4923df4n/a Heodo
2020-07-317nkfvs380716.exeexe 174789d55b2d240c1c4ba344ddf3dcf9c83c2af1fd0eaed83d7b91641e5e38e4Virustotal results 8.57% Heodo
2020-07-31zdh0nk3576003327.exeexe 065ec5088be08aa5a171ac7ef06acc9254b032dad84d9cfecc5c215b2fddc20en/a Heodo
2020-07-31c17fa8ln567631.exeexe d9221298ae317a80f5dec767a99d5df02a9117f56377078cd865caacb3908576n/a Heodo