URLhaus Database

You are currently viewing the URLhaus database entry for https://onefarmdesign.com/cgi-bin/g_r_f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427001
URL: https://onefarmdesign.com/cgi-bin/g_r_f/
URL Status:Offline
Host: onefarmdesign.com
Date added:2020-08-07 06:33:15 UTC
Last online:2020-08-22 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 06:34:02 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:15 days, 0 hours, 50 minutes Bad (down since 2020-08-22 07:24:26 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08VtM.exeexe 58814046bc0f47cba03d426edbbdd79c3105dbd6debc3d9f1031a2491c136713n/a Heodo
2020-08-0816f3EN.exeexe 2d85b5b21f507eb6b0e848fb2fd20fa13a454d1ed003d08d1a27174df9f18d30n/a 
2020-08-08XwuIAfdO8q8uQQM.exeexe c2ce83cd2225e79a7951dc747c974729760cebffc6d141864a952ce0cb3d00f2n/a Heodo
2020-08-08Sbv3B9VdboINOy.exeexe 8a37523e46e6f4b108357ad4c66995829f275cf739d3a1963e5a69744e5b73dfn/a Heodo
2020-08-08NyOSiUpgr3uXwlPR3.exeexe 6127fce34de3f85dfb648886e31d8b5086849607fa428b666814768a5d89201dn/a Heodo
2020-08-08wugOqpXDGznWCod.exeexe 421531f67ca856354afb1a6037f1dccaff54feb6afc9d62a2d4395358fa7f72en/a Heodo
2020-08-08Y1L.exeexe 74a298683386da417b0d215b203e95fa65022e18e176f11bd15604a98b33c20bn/a Heodo
2020-08-08V7CVUSdoDpQ95.exeexe 9374ced8d66525bd19a8f7a24c0bfe277f768a601f724023700407bc0da0755bn/a Heodo
2020-08-086JN4Od.exeexe 015ff1c36eb0e191b084cdd4b7d9b5e652b5a19247977aeb75be979559cd54d2n/a Heodo
2020-08-08zFKclIxa7kCJ9h.exeexe 5d7511e02d3371b39d669bc009d1643e00c5274c83e532e6f3695d0a912c9e85n/a 
2020-08-082HKme1tXjQuvhC2.exeexe ac25d9814fa6a99328b8aa9bd5df2df3673ee6e0f10b45a6cd8d80bd5474c261n/a Heodo
2020-08-08EYYenMH3gb9sFF.exeexe 959679b5f75a1df7fc74ae205527da75bfb1106d9579685174beb3eeadc01771n/a Heodo
2020-08-08b5P24AFrH4vVWUnnYB.exeexe 2ada5be4652a49ae72405db687923996339e2e177104a92977248ebe20139d5en/a Heodo
2020-08-08sxQlmQ6cYLWI.exeexe 268bb8c7e56414c83ae774c7fc53286872fe44b87734de585f0f5251a73830bbn/a Heodo
2020-08-08tLS84m.exeexe a150d996151368f427142b0e7f2ffbc2e067547262afdcd41c26001bae34fed6n/a 
2020-08-08WqML.exeexe d87aeeda57d05bc25858b6b604dc9d8f19a5c0cbc6afa6656b6597d1dd74c8b1n/a Heodo
2020-08-081x.exeexe 7c6e9554cb8e7e560d5cab54b02467f37f93b6d0ce7ee298fc781eaf30600334n/a Heodo
2020-08-08kcCiJFJ.exeexe 6ce6522aec751d48911be2b1282ed3397c69a7aa8531c207d50aec6f74fe82e4n/a Heodo
2020-08-08Qvvf.exeexe 4b47dcee37aa590563d86b2d8573c204b6963db9f8a35ae6cc3b9719b656b1f1n/a Heodo
2020-08-08T3YTFQR.exeexe 15490d613ce23363bae89b3bf318e2a19912b653288b98829a3d2bd5c76c84d2n/a Heodo
2020-08-082kGPU6pn0J2BaQPrAT.exeexe e7775bb8ebe3d60f582b4db676a940e5d32d5a4d459057cf6612606c83ee8473n/a Heodo
2020-08-08bVKvEBxuwzA.exeexe 0c7530ea5e0f43f8aa4245b2022f5de0d20737726da2d028308208e8bd1ff183n/a Heodo
2020-08-08Sn.exeexe 5172820c848a59c8cff84bc7c62f10c9ea8b9b3f0f64d4bd94f5de4a18cf4a2dn/a Heodo
2020-08-08n45IbWv7tOhWQUatwyDW.exeexe 3760f45803632885c0c6242e48714292270d0edf84d476f76e318f6441cf0345n/a 
2020-08-08f.exeexe 23fecf9ae662273577175bdac7608566c77ab5360b78fd017c8aaa88a16b9e20n/a Heodo
2020-08-08QDudu3NqU.exeexe a172503528cb886036d8ea1dcb21fe93b10f7fe8c7be9ec0f8af83d945bd9bd7n/a Heodo
2020-08-083Qngb.exeexe 2a4566ea6e0bdcfd234ff6bf3838613d841ceba58c7d5bb2d8c12002b723913dn/a Heodo
2020-08-08u0p6UPAevfFVJOIaD.exeexe 733b959bb657d2eba5309ca48d3c0f06ede092d734f74daeda051fa814828a85n/a Heodo
2020-08-08nWlKL3PdKyi1goa.exeexe 1f1dd7253cbc9811e4dc98787a0277fdf49f592b3573684b29737058e302f21fn/a Heodo
2020-08-08vMm7GD71C6vZwDL.exeexe 72c65eb62ebbf74327a9692197e8b09e09671c28bb5b6c3b5195e7db2a151c1dn/a Heodo
2020-08-086nv2LwE3JoZGNhIYOn.exeexe fc26ed0479d1414583359f4b50866299bbd614b3d2296ebc8625279c1daed44an/a 
2020-08-08jpZL0dyqnJtl.exeexe 5585c8da6aaab97d909d313164ffa37e1ac316daf41191994dac297e09096859n/a Heodo
2020-08-08T2wqJ9bE3wY.exeexe c9321d02c54c630c0afd11c40327b9038994852afa199ddc8fbc5e7edc6aafdbn/a Heodo
2020-08-08SBVSJO1Mch5iavbWX.exeexe 8ae182752c77603467dc3671f59986d0bb029283dd3d8ab262e8b60f00546c84n/a 
2020-08-08HfudgO7jNXRHv1.exeexe 6cf810d82201225262ebfb287e33072a0d8a17121f790e0713fb1a1fae5569ddn/a 
2020-08-083WO.exeexe 7a34285d9fdb945aadb0d449dd1dc176ebf32f1afee360e7e1438597dcdc2062n/a Heodo
2020-08-089psZOfB.exeexe 95e175337ee2272ac0a53a6d10f80b0dd46009bf002ffc4d6ffbe61c8aab1908n/a 
2020-08-08zLOFS4xbmd0GlP0.exeexe da1cf3963cd1ba5eac9db1e2d67eb72f0412dacdb3282c1f081cd664d3dd5771n/a Heodo
2020-08-08CyQe6WqO9LLzf.exeexe d60588400d08b16c6cc887c837e9fa8fa2c6075046a9532081b0d408aba4f8cfn/a Heodo
2020-08-08H.exeexe 2fe8d928f05f63b6222fbd6cce45b98f26287adf327deb01fb1add198b51c1acn/a Heodo
2020-08-084.exeexe aac0b0dbc761e7be30d8e427cc3ff251b9d61533611334c1bc2c0a0a0acc72b6n/a Heodo
2020-08-08gAupBCfcmRHL.exeexe 1c7f6a1bc166e5d79965213441cf914dd4abf0c93b20f133b50ff848604ad146n/a Heodo
2020-08-08Rz6ZaQaHxJjMvl4UDhCu.exeexe 20e6c913187655914408d3858026dec4409d6061f3869c3c5436cf68d319d289Virustotal results 15.07% Heodo
2020-08-08H.exeexe b86d886c8589465391ebd8a4be21e22486c59036b07801e9c0d0ed42f5e94278n/a Heodo
2020-08-08TLVR.exeexe e8da54f8e7aeaf78d749c3a34aa75c95d4c416bd4b96215d85565722cc7d6486n/a Heodo
2020-08-08KH7d299FFEqwwARkVgQV.exeexe 37df0459bda64df25ecbc480f7d202281e2e7187ad06350ba87c057854565561n/a Heodo
2020-08-08GjzhUZ8.exeexe 1bca925f87966ea65dc7bf0d98ecde998b4551809462f2406843d47bb7af002en/a Heodo
2020-08-08901wlJlDN9.exeexe b42b6c65f571b23e857d545e06ac3584ff06dd860eabed36a1f5adc7a0518dcan/a Heodo
2020-08-08n2ZaiomzEfos93bkQjwV.exeexe aef51f68910785417b3508a16339aaa84636202e731d8b70dd665de7eb634628n/a Heodo
2020-08-07CCBnL1HK.exeexe 91de2d6affbd7f4be2378e304d1a4dec4871f5071466e29ce429cf853c6c2d68n/a Heodo
2020-08-07lvosh4PCfMExDb.exeexe 3a0dd87d625dda9eb052e8ad93213dc2cfaabc68b5dda1f0680637fc5ee4a710n/a Heodo
2020-08-07WzwF2nwLo7.exeexe 06ef6dcc3638dde13e31ef8c4055bd7184475aacd98047bc89214575579cb233n/a 
2020-08-07xk8tv6Ppp0SvieqDyC4e.exeexe aaf414db874a298c08dec7ca96ab7e5da446f08e97207951bd633f90fec66800n/a Heodo
2020-08-07l2hHDtTjf4USo8RMa.exeexe f9bfb6bb88f7038ac8b2a5f2edb3c77426a767119c7e5b517dfebed518ee07b4n/a Heodo
2020-08-07KYy8bxP6PxgB.exeexe e8e67402f97639b4a0a6cedd94eaa20f32dd67467f6e8fce8025682d71e3d157n/a Heodo
2020-08-07xgf5Q.exeexe 59124db0cffedd00e9c24515c308dacbba87ccd3195bb0f1028078f954c58492n/a 
2020-08-07tTHQkEoOOOpX1uyh58.exeexe 270b0d016365bb2e885a069a3f34211bad2a77865762fcf1e647041b6b470658Virustotal results 11.27% Heodo
2020-08-07YuioncL9Mm.exeexe 987e0e9509b2073dc30a697717571b9b4d1f9f90ce1d1d35f1513175eda1ce7cn/a Heodo
2020-08-07HCIijEP.exeexe c5566410559be5332df0c1d6f4c672394e74e084bf8bb44d98266285fed5d2fen/a Heodo
2020-08-07Ly.exeexe fdc668454de5d4383a374f18e7afe85f98cbfea084fb7e0ab6c381ed8fd7c0fcn/a 
2020-08-07PdhKr.exeexe 5422869397ed03e5618f992506ce1b193e7c1994989a8f70bfac91955368a10fn/a Heodo
2020-08-07yhIgYTUy2.exeexe 894a323fbc4194036b768ac19be8416d90859b534df115d5e5f08eb4d3438fccn/a Heodo
2020-08-078GoZ5SCnA70CXdV.exeexe 0e77ac574baeb8ec9b051ceb2200ddf47ad846f9f9f051b38b53884aa58ad068n/a Heodo
2020-08-07I3WKhBiinXPHshB.exeexe 9244a604bf7c4b78c30a49b25caf9ea4ec5408ac59a57233e82433064f755f07n/a Heodo
2020-08-07yUB38nnb1GDy3VgxXd.exeexe c65c55887b1c745419937588f771f0330416f755089d1a500ff14b019bce53acn/a 
2020-08-07Cm8.exeexe d4b7922ff4a760472721123fb3399d3b9c7620277fc5f56768964961269b9116n/a Heodo
2020-08-07B56qKjj4x9gp063mT.exeexe 895026b007fa23a01dd1bfbc0b7fe7b2fb347172fa09a86e9342f62ab6f593e7n/a Heodo
2020-08-07Zz.exeexe 9234c52ecddcecfab2465a3bb02ff180979b7ae0ae49f226890fe79055163ae0n/a Heodo
2020-08-07jToO4QQiRKvDIje.exeexe c9c56533a3b757a8bbe022d9f5ba76a2d9e37c7f56f19c6e438af9664c98d666n/a Heodo
2020-08-07ptKdq0FHpp8Btxy0.exeexe bfa6d0c04e81bd957cbf262ca85c57f25494eaf7014cde9ed28b8d74d025e007n/a Heodo
2020-08-070PVuSLVmOO.exeexe 0ab7810971112f512a5d45cdb3584ad4870deff2d897e3885624407e1985f08an/a Heodo
2020-08-07RpUaX.exeexe c697e0ffd5bee8d5db53a8a053812a0548d0488c1e37d9e3152baa4ab0b63126n/a Heodo
2020-08-0720BIQL.exeexe d0de76f87cc7320a7f05b17df534389c38a9564b686370f18d38eb11744e86ffn/a Heodo
2020-08-073VXBgg.exeexe bc6b668cc6e46e595641e54661be2474ad7e4b9120718099d2b3e50b12dfa48bn/a Heodo
2020-08-078tLUas6dy52.exeexe 6367b87ef44d86d1c2ebb908f2db38f49ce580ef9b4adea6a15e923f8fab865fn/a Heodo
2020-08-07xx8kx9s5Vw38.exeexe e82c0c2568f0dc4cc1c9406538087df372c003dcab1337500fc21e6b530727c1n/a Heodo