URLhaus Database

You are currently viewing the URLhaus database entry for http://galaenterprises.com.au/site/6kw_wao_ekmv5w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430123
URL: http://galaenterprises.com.au/site/6kw_wao_ekmv5w/
URL Status:Offline
Host: galaenterprises.com.au
Date added:2020-08-12 10:36:40 UTC
Last online:2020-08-12 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 10:38:05 UTC to abuse{at}aptum[dot]com)
Takedown time:5 hours, 46 minutes Good (down since 2020-08-12 16:24:45 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12fDDt4P2ufi7jLDboTs.exeexe bf63b4b8f510e46f8e970d9a06a9616a029d32ab115948d3cd37ed4512046b40Virustotal results 23.94% Heodo
2020-08-12zM1DSMn.exeexe 4f4830a5bc27f6bf4a7831839872d117b9fbf7fb551255bab2db52d95182613cn/a Heodo
2020-08-12nJ2iY33LLpLojbpHdKm.exeexe 13001abfd66893cc106dd1cf3e7807f9a6b345a9ed562dee085213c93cae4aaan/a Heodo
2020-08-120LcRM5UcwnOODjVS.exeexe c4c417b2f09d17b47b8035f4a9ee62b80febdbe5d6cb1b5a6f7167f303c65869n/a Heodo
2020-08-129GopCFT63.exeexe 0e32d86d3b8ec9abe4e7615e2b2e8a169736a53e38bd26ca546d211a70b92508n/a Heodo
2020-08-12T7AG5QQ8OjT1LFCKG.exeexe f2599b68ac40ec462c203f65576a60c0723838f2e19f68bad3bc4e433f98ae57n/a Heodo
2020-08-12n6VZ9YyuDSW6vPNM.exeexe 895343d3b12715e476c4ec10a2e779446963dbb4c7df9a370569db0450d41e0an/a Heodo
2020-08-12kjAPg6.exeexe 2861c92c683045f654e200dc5d4d105856e1f0cf907b19c4cb4060e8d1d1b0b1n/a Heodo