URLhaus Database

You are currently viewing the URLhaus database entry for http://kjnk.ee/awstats-icon/eOn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430072
URL: http://kjnk.ee/awstats-icon/eOn/
URL Status:Offline
Host: kjnk.ee
Date added:2020-08-12 09:38:20 UTC
Last online:2020-08-13 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 09:40:05 UTC to ripe{at}up[dot]ee)
Takedown time:18 hours, 40 minutes Good (down since 2020-08-13 04:20:51 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13brn4869496.exeexe 79a86ad57b37f6a2648cc7a367ebc2ff94f33134f84b89fb3b362bd253867836n/a Heodo
2020-08-13zw966.exeexe e782aa2405efac97175bebe99142aefed9023154ff230e915ff19280873ba338n/a Heodo
2020-08-13sk4z6395120449.exeexe 40fc0c307694cd49167bd8df9d88502cd8195383788fe1880a91c70feebaadcdn/a Heodo
2020-08-13mhzktvnm94809.exeexe e3d776507de7e72617d476572d612d4ef148c559333c724bd0d052ec5fd8143en/a Heodo
2020-08-12ab31649.exeexe 84a213b0cbb8a7612e09d03b6c3890fb61bb4fd8a8be63671062c2f4f34ce0ddn/a Heodo
2020-08-12p1r012.exeexe 661d7a9042ad16719a09197af7aa800820974ab0c0f9af67683e327755ff0735n/a Heodo
2020-08-12zzatys06464.exeexe 3666f7517da02d91d56604c21129f54a44c18f809e3858896a95e2a436ca91c7n/a Heodo
2020-08-12217ltm68475629456.exeexe db1175670e4589430e592341f3bbd2a27998847b62a97b37d21e93f1275de0fdVirustotal results 16.90% Heodo
2020-08-12qli8l78np1114885747.exeexe 6a795bbd320916c1f41d289af70129b007757617a38cb9029cd11552e3894f20n/a Heodo
2020-08-129oheij3449757.exeexe f144a88765c6ee656c43e0e651b48bf065e755ea37a1416d4020beb24e3c8281n/a Heodo
2020-08-12ttm87825.exeexe 9a238650d80a54c05dae5a7f6b2abcd0ef1d4c40500f32e1ad883f9e12191a08n/a Heodo
2020-08-12jyuc704.exeexe e933673a305f294540a1804b8df57b27acfc121237cf39b0f330e4fe5bddee52n/a Heodo
2020-08-12g1ymunr977.exeexe 5da19d73e4d1dd27d87f4b53b888d2f937a68c2cd3d41e44b581e420aa219e88n/a Heodo
2020-08-1299632369.exeexe 9a14ac706b44a656d2bfc22dc01068673f5d6ed207dcc41b0c407a13e60327ebn/a Heodo
2020-08-12ipluny7331208.exeexe 28ced160b8b5b50e32f1060f304bf5befe1421656bbdde2a93d43f6bb20756ban/a Heodo
2020-08-12nu4az7275690679.exeexe 1ff305d44e8a35286fb92f8c4c3455b00ddb3894f409e0ad2185dd4993f8cce9n/a Heodo
2020-08-12s7i572.exeexe 30497d04e3ceb49b60c61234c18ff64b4ca8db6841af15a87cc621b602dd4445n/a Heodo
2020-08-12avy4l8grnx330037673.exeexe 299a6c3016b932beccfd7a22b55afff2ded0a08022a5098610306247d895235fn/a Heodo
2020-08-12ftp53r053709244.exeexe 052f9e23cce9bd67811058725c5d67b7fe0a02b0dc574ce72b4c00c489508e99n/a Heodo
2020-08-12i9metx330093.exeexe 7fc8ffeaf15ec29433dbca989bdb8e89630dd6697dd6484c12f2c6ec9893f083n/a Heodo
2020-08-12iey587603818.exeexe 60645fd3c569eb81bc2bc4f0ae9cdd74324d1e90e27097a3f4e005671fb2f9adn/a Heodo
2020-08-12ut6u1zks67308.exeexe 490646081c4faed7b1145a8d58b68176373775f6cddfa0bcef220c2fe3d46fd1n/a Heodo
2020-08-12c64340292.exeexe c22cc23a2982ba6bf4c855e0488b9c8b0b94d39b8ce0172d4354222edffeecffn/a Heodo
2020-08-12i764376.exeexe 1a29775e220cb0e4a3b49756c868259bb9b69acbd714363907644fe434dd9c77n/a Heodo
2020-08-127c0a734e213227.exeexe 13ef223b34f4ac96de2abc716c8d377fb0961a515e1b6a05d0eb76f790fc8d51Virustotal results 14.08% Heodo
2020-08-120i890870.exeexe a359aae83b6f300ea218255d44a52d925e0e9527517d4113a3419cb423677837n/a Heodo
2020-08-12m5abjbx20.exeexe b498b0bb1ea0627d4d25e4805d5c6ed0ad3d0051b264755a68d96792aa2bbdcdn/a Heodo
2020-08-12vdvjalcj1516074.exeexe bd8468583368a3058fded7ecf37b893ac69b2376fc248748d842076657246a9bn/a Heodo