URLhaus Database

You are currently viewing the URLhaus database entry for http://artexproductions.com/cgi-bin/xHdbmk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422867
URL: http://artexproductions.com/cgi-bin/xHdbmk/
URL Status:Offline
Host: artexproductions.com
Date added:2020-07-31 15:07:08 UTC
Last online:2020-07-31 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-31 15:08:10 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:3 hours, 32 minutes Good (down since 2020-07-31 18:40:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-3199uw7Dk8ww9bkPo1Yja.exeexe b424b3cca4c992e64bd91e942d4c1d1b3a3fa8019b0eb2feda226a89e0ade3feVirustotal results 13.89% Heodo
2020-07-31deUC0ljMp.exeexe cf32b5211d1b665ab6d687ef5748939bcb0c28c59724bb8aa0757f7513b8a456Virustotal results 13.70% Heodo
2020-07-31G26NnhfoJEcUPk2K.exeexe 7a7b6d14f8d7cd38958c30d84c67e1fe07da8df1365f3303ce922b10eeb81311Virustotal results 11.43% Heodo
2020-07-31urR3eizE1epXG.exeexe da562414ea2d2c2d8a7839fadd378f1cd95da343ebbb8470de9c517c3581418bn/a Heodo
2020-07-31uhcieguzmPLA.exeexe b14917d5173bb4eef36533e41c18aef339a5c823fa93f5366fd3941d905c9abdn/a Heodo
2020-07-31gSGSrOhk82nWfse13oj.exeexe 9dff8f10809f0afc7d454de244cf33c6b73e140b9ece37ee547ab82d4ef4b4c1n/a Heodo
2020-07-31O1lkStu.exeexe 8bbcba4a323e6eab75c5963bf6ebb993f142b0b792fe8a3c2d3cb2ea92912d24n/a Heodo
2020-07-31ZVCDnp0KtLUfnu.exeexe 4e456e2eb7cc605de4d435a4c43bb46c2d637458a0f43d5c7739725be7e3f8cfn/a Heodo
2020-07-31EI5p5M7uLF.exeexe 5fd86f1586f6e086a378210fae055c0ac3d6d2724ed2ee3fefb734929d6dcb01n/a Heodo