URLhaus Database

You are currently viewing the URLhaus database entry for http://watersdesigns.com/cgi-bin/XXRfKgf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426337
URL: http://watersdesigns.com/cgi-bin/XXRfKgf/
URL Status:Offline
Host: watersdesigns.com
Date added:2020-08-06 14:12:12 UTC
Last online:2020-08-07 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-06 14:14:08 UTC to abuse{at}liquidweb[dot]com)
Takedown time:1 day, 5 hours, 13 minutes Poor (down since 2020-08-07 19:27:13 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07JfkMSBbLN6q.exeexe b95f42516158d8b67985cc81883f19754845a4400598b5225c3fbed31b6daaa9n/a Heodo
2020-08-07DzvBAA.exeexe 4aceccc501bc312facec14eec44d61ee3e21daad55e5140a04d1bc528726a71an/a 
2020-08-07lW6PR.exeexe 8cb9b305343725ff0366212e7760b87408929e29b519ea86bdc504f13b836ddan/a Heodo
2020-08-07LFyyPVn4QDax.exeexe f9ba0c4810dec878edca0d90ec6b1907ce37b190788ad3d7f98faf94a057db48n/a Heodo
2020-08-07nO5g.exeexe 7c1b3e73a1d4519244b90b335bd1f879a70617a97573af34e30d061bd52f6e63n/a Heodo
2020-08-07G2BoxW0h.exeexe 49bc0e1bb7d14113251770882be447c0577e63be04e4c78dda3dcd2b36738201n/a Heodo
2020-08-07E50eo93xaN79MkIHzilBp.exeexe 489f9ac65bb1857d40ee7c09da0cb71d445d01db1edb6af134819af7d1dff089n/a 
2020-08-07u6NxPNJk.exeexe 6e5d56b974d3e33e984ce496f9e03b5d22cf160c48317a1621f8b60c205acae9n/a Heodo
2020-08-07C77AGz9GDBRAol41Xime.exeexe 07a63e2752bc914830d0de227222998be96381d24ba7aab09c813336ac6c3d57n/a 
2020-08-07ThPbdwbmNwTU6AmeC790.exeexe b090bf9a6f037dccb0a30dad84ec714535e7b1bd4a6faadee821243612b15e71n/a Heodo
2020-08-07XkNHdYUw.exeexe 14aeb3554931c9e6b01b077c8c0a30e4655c5dd699d37b7491a29be555b270f6n/a Heodo
2020-08-07hqLWdFsyH.exeexe d3abbd31563eed309656a122e59d2535f46d7bb1e3fd2edc366d401ab6c8910cn/a Heodo
2020-08-07t9EtDhhipw.exeexe cb61ef1c62b708fc19900bd1625bedb6cf52706f9803d80ac3ffb48f043d7fe5n/a Heodo
2020-08-07RmSlz.exeexe bb99f751132145b26f4d4e05093139d0761c34f507cfb92d2b5303870405f43an/a Heodo
2020-08-07gWzJoP.exeexe 658051bcbc235142ccb8faa51d77e86363bee29c273467302ef17195b0dba87en/a Heodo
2020-08-07vCtu.exeexe d8d8e2e35606c7eb20fb8db0ec616077f616d3fc56409998d6735b9b6034a6c6n/a Heodo
2020-08-071CszmlxdoyWfDz.exeexe b765f154536b182b88c5ce50a2ed6e3cfb8c7a9374f38485a49d9ac6c3111145n/a Heodo
2020-08-07LFzN2vCUsrdHdOJA.exeexe 504b19e99156b916c1cc3b9370fcecd2a86b1aed1083e252120dafa0ca3de5c5n/a Heodo
2020-08-07Iux0v3t9GFkrtNvQ.exeexe 4efd115e729225b0f76fd2ad72a1dd31dd5482b3c8a6c093ff22c2bda836de47n/a Heodo
2020-08-07oecyR0.exeexe 36fe123de2f6c224bde392d05ee2d657390eae37e01c534467cf4759ffce1bd2n/a Heodo
2020-08-07SKmtkgrrX8.exeexe 3ea802d8133ad81dad3b169b22023970e93d3dfe4c65855bfe2e15fec00817a5n/a Heodo
2020-08-07sKx.exeexe 5188783ff53d67ab65e97104e83550d66db07a379f79c2d328208c0636e1b6c1n/a Heodo
2020-08-07TMrOif6zKhhi8Ovrm8Tpv.exeexe d4e7def33133e95b12a7ffa4fa9a0238f5d479d624707180f2cbb51a732cd61dn/a Heodo
2020-08-07ERHj.exeexe a265af6bf1bd257ed57dbba8ef5b8d8632cede2699579d030c3d41d894b0e7c6n/a Heodo
2020-08-07ME4NK8.exeexe 80964d055f805be573e8fe31727b28ceeb56ce9dc937a14f653a4cfae1fb55d0n/a Heodo
2020-08-07G8G7opYc7wG5.exeexe b340d7fa69bb3d93318a956b6f0264dbc122dbb62b2daab8f6824e2bd0b29f7dn/a Heodo
2020-08-0741EEE8.exeexe cbfddc2972fb00b56545c1b450514c6caf4c2065988a0c93310b034bd3b33280n/a Heodo
2020-08-07xFl9VuQgrtu11LJJ7Zrt.exeexe 0f90fe8d443c1d8892521091ee95f2e9b67dd80527b44e9b67eb38c5bbdfea95Virustotal results 5.71% Heodo
2020-08-073YKJ8ZzodPXtvqOK.exeexe ce74547ae774474acf62649bbcb19dcb63d8930164525172719b2a81ed2e7ffan/a Heodo
2020-08-07Yr4TXy6itK8FD7.exeexe a1a9e85bb2e15657e15ccf0db793b10891dc235eebe930fa6bbb89f4def91723Virustotal results 5.48% Heodo
2020-08-07f03ij.exeexe 324f856292c3925b015edee1df2c28428182a706ff298d06cf89f096d89c275fn/a Heodo
2020-08-07aFdD4573lKof.exeexe 6e87637a39dd31b76f5f65bbd4102b0f5ed0040b85a45e41bb5cc2b91f3911a7n/a Heodo
2020-08-07lU2185CWVsENkgrS.exeexe 1e4f081ba31c894d456fca5fbb80fab0ce7cc87c1240cfcda797e41759517616n/a Heodo
2020-08-072RpPfjaS.exeexe 500a76212b3ab0bf2d480036f91360c0e886f310ed59b2b47c2904e0e4d41e77n/a Heodo
2020-08-07P3VQfVRNNtyjAG2DaW.exeexe f9b76689eb17c1ae665987e9a2f05dcfc38d26f3a8219956b041487b968c9faen/a Heodo
2020-08-077gLnWQRy.exeexe 6ce2337ed32bdd74ec1ae18341d25573297eb4449b3c4f23551896615a6ad93cn/a Heodo
2020-08-06LVLITQbOAhqnQuwvZr.exeexe 1f392eb01b893e496b02ebc280119ece594a66865b510750921c1fe69da7883an/a Heodo
2020-08-06PkSBfrcybv2Fa6HRn.exeexe 99bf5fbd8c20fb034f49b9e57144e8a20b60c8c8a3a7a19692a87afb498dc01en/a Heodo
2020-08-06iyTkmPqNuMiQwzBjkqFVM.exeexe 2c5eddc5b7fff76e944fbe69317c73c6658192fde1d2922ea83ef843999b5a97n/a Heodo
2020-08-06ERQUt.exeexe ce59862eb27ad5dc79ddc467cef0f71e9af1d1317083f45816362bc9dbac69ccn/a Heodo
2020-08-06YcPNegN83Mmvv.exeexe 6d1880762b30d45525069a2a7c609ba40795d3d582072fc702fb305fdea64e82n/a Heodo
2020-08-06vfzgJaO.exeexe d23ccfb28aa8c5a787162114e60cce38e0ae9cf707cd07dab635befde13a66ebn/a Heodo
2020-08-06se07XTJhvA.exeexe 8df1bd2ba10cfb85682215e2d10a5c4549f5322e4664bb64c091c0a3b79be9a0n/a Heodo
2020-08-06BTrkG3qhiTZPDG1F.exeexe 7904bfd3eb40ba5b8a6a51056f6a63d89ba82d6c2ec08ee6ba5f7d2ef889ea93n/a Heodo
2020-08-06i4yOWc6QxYvdd.exeexe 1378bf81cd7adcda287ef90d206861b5dcf017b8d0db1e78d43b28403cb3b855n/a Heodo
2020-08-06bH2EU5dRb.exeexe 0ae194b6adb7940be2352e2af836e598c36e6f3a9b914bfa362661e1cb9aca49n/a Heodo
2020-08-062h0yxa0YmLtgOHJ.exeexe 04bcce56d7fad29ba0f6584709cb6af980a9931358b1e35e467fdbf918cb8a44n/a Heodo
2020-08-06I7MiDjahw6VyxYY.exeexe d3e70c3019bbfef8dcaa052884c35c5405bd57fbf597c8afb9ad4678b51e3e99Virustotal results 33.33% Heodo
2020-08-06aqWBeXVLjzhJ54HRz.exeexe 57025594c38dc646befee20609452f5d8737a47816e05ab13bc8b31cb6b9dccdn/a Heodo
2020-08-06yUA8DtGQ.exeexe fce720dde04236f160f63674c0939a7fccd3e8a9e05952983976908b8f71cec0n/a Heodo
2020-08-06afA9d1sY.exeexe 8122ffc5b9973ff00b57b79fc153eea53611e4fe3b285b1d4cf3c6f7e8d6b4f2n/a Heodo
2020-08-06aSjeiybr7KdZ6Pu.exeexe dfbfb5ba00b2c8bf0741f490441dbbeabe31e4be3650e43f18283cae0c1f0062n/a Heodo
2020-08-06zA2B539nHyKxPDP.exeexe 2ba850df7245d328ba1a3d8f2b3ea2656a4182c49ddef8cceda86cc2819af9bcn/a Heodo
2020-08-06LQ9.exeexe a77a26dd9cf714abd7260798cfbec825e81c90580b12c4ecdf80f25159004ef6n/a Heodo
2020-08-06mPWUiRJAqrxQViasJ.exeexe 36a981371234a52f048b0f9a42f1add9de5b48e5b64a24aed00f34d5d7eda25an/a Heodo
2020-08-06NwtKwJEPqdqw2YV.exeexe b3a63dde84fb84a95617c001eb68f90a254593a29899ceddddfbafe6d0e2e681Virustotal results 29.17% Heodo
2020-08-06dhftGjv06.exeexe b50cfa1451a5246c0d14c40b6da559c2c88815cb2a5a7d2a9fdd3b076211aac1n/a Heodo
2020-08-06heMzzfnfH5qdemosT.exeexe c01c487c98820433c67ef97f057fee992972a369c442a1b7d6f02b2b11d9e9e4n/a Heodo
2020-08-06ph8.exeexe ecbc139d466b80be281a6dce0c368555713860f77d3c10d019692d33319bb8c8Virustotal results 31.94% Heodo
2020-08-06PKD0F.exeexe 43299dd838759e0a42fa566345a457c86d2a0c9462ad958103414533b7f18cden/a Heodo
2020-08-06AuDRIfQdzK6j.exeexe 6c117864ebec57bc2125fad17bda9f082b81b8116853c79d9a0536f684ce3860n/a Heodo