URLhaus Database

You are currently viewing the URLhaus database entry for http://www.boekjereis.net/wp-includes/uY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428810
URL: http://www.boekjereis.net/wp-includes/uY/
URL Status:Offline
Host: www.boekjereis.net
Date added:2020-08-10 19:12:22 UTC
Last online:2020-08-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 19:14:06 UTC to abuse{at}as29290[dot]net)
Takedown time:2 hours, 31 minutes Good (down since 2020-08-10 21:45:44 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10mRKjvo9O.exeexe e8c07cde12fe8d5fadf7ff42fd104b669908276c3d73129a616264d95ee56868n/a Heodo
2020-08-10Zl4fJOfv6C5mwR.exeexe 3eff22a55aa83790a137a365c979815745b71c2ce6f209413db7ab0bbb95f270n/a Heodo
2020-08-1015Zbv.exeexe 6576af06ee27163b1dbba7864806c458a4e1cf96fe1f5c22fc52baa321bb6b15n/a Heodo
2020-08-109OkyoMANmIvTI4yWj.exeexe 0f8d6a3a6cacc989f7a68e39e781a09ca913bb0fa609d33e89b7f5b09adf76c5n/a Heodo
2020-08-104HgQsY.exeexe 3fd5faf504f3180116c1daebe78516fb1f53f004fd6aa0d45580825561061b00n/a Heodo
2020-08-10bJd.exeexe 3fbb10c70101476a0a08c7cd19a0f6b995b85e68fbafd64f2977f70a6486f02cn/a Heodo