URLhaus Database

You are currently viewing the URLhaus database entry for http://seatrade.com.eg/index_files/OGUwzJl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432969
URL: http://seatrade.com.eg/index_files/OGUwzJl/
URL Status:Offline
Host: seatrade.com.eg
Date added:2020-08-14 07:44:42 UTC
Last online:2020-08-14 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 07:46:03 UTC to abuse{at}tedata[dot]net)
Takedown time:10 hours, 43 minutes Good (down since 2020-08-14 18:29:24 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14f09pe2ikts208557982.exeexe 0728919c52c4e4389bf042a40cee4393e0f9575b2398b712ec997308ef955bd3n/a Heodo
2020-08-146jtn7446.exeexe cf70938fc6661eae37fca21f4f41e16f068a5e07f5ff492307d535dd19691dabn/a Heodo
2020-08-1435qavjq9522814.exeexe 8b418816d2cddd8ade86f083283f6979784eb5ff648c0e427746ac698f9c097an/a Heodo
2020-08-14ug2ml818.exeexe 5aa4c2f877723719e1c93d4b30c1072a71071d24882342b0b15862c83eb40274Virustotal results 19.72% Heodo
2020-08-14jrusqzyw51027.exeexe adee4199408ca89ae3db71a92bafa124e1b065122334643e92c8dd183c131934n/a Heodo
2020-08-14etx4s337134.exeexe 404c40da27db6b890da3d587c18f534d69210138e37095d7a2b6a8e49505282cn/a Heodo