URLhaus Database

You are currently viewing the URLhaus database entry for https://kissanime24.com/anime/jgvgw_eu_2m5bw0ae/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431155
URL: https://kissanime24.com/anime/jgvgw_eu_2m5bw0ae/
URL Status:Offline
Host: kissanime24.com
Date added:2020-08-12 17:19:12 UTC
Last online:2020-08-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 17:20:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 37 minutes Good (down since 2020-08-12 19:57:13 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-129Nf22YGoelSU.exeexe eefededf23d7bd721c08ec04b70e3fb2e299d158d22ae13b0240aa99eca830fcn/a Heodo
2020-08-12VyOCjcP2.exeexe dc065abb663d05b73d3589e546fa730ec85566f5df5624c3b3b35b5fc6fde6b9n/a Heodo
2020-08-12a8jzuTUY42KTPCsM.exeexe 2fa01a44f3231fe11dd9d632c1e0c94725bc09e55ddfe0ecbfe861f263cd85efn/a Heodo
2020-08-12edNTDYihlzi3vc.exeexe 6294892f4ddb1e579fdf50d6e15a782ebf80b2d688d66ec0e7c481a1e74fa2ffVirustotal results 11.43% Heodo
2020-08-12K8juI.exeexe 6f3a61ca6376109601d131228e7e1cfc161109f850ecb7cff71ab4bcc159d490n/a Heodo