URLhaus Database

You are currently viewing the URLhaus database entry for https://adhd.org.sa/sub_mrs/Zj0ZrG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436444
URL: https://adhd.org.sa/sub_mrs/Zj0ZrG/
URL Status:Offline
Host: adhd.org.sa
Date added:2020-08-19 10:54:21 UTC
Last online:2020-08-19 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 10:56:14 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:4 hours, 43 minutes Good (down since 2020-08-19 15:39:39 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19xPQepdMN.exeexe d7bd99abdb734505805e5544736ea4fe2c029081371e03f59008ef145cda3790n/a Heodo
2020-08-19PYZZymfdJI.exeexe eaa704ffb59ce78b5cf3fe2e0bdd3294de17831e0aed700cce617477530149d8n/a Heodo
2020-08-199gUtFDW.exeexe 8f634aaf124a73f77138606ad31d8461a4a6d6842c2733b26aafb0d42baef427n/a Heodo
2020-08-19pafYL7ZH1s1Dks6dzRO.exeexe 1165838e41174443fa30d42f2d900419ecae012b92c4ebd1af67faef56336250n/a Heodo
2020-08-195oO68Llqurk.exeexe e11e765d1455c5ec5ff5e0cf1de9b25296b35192e1d191c7b47d217e610d49can/a Heodo
2020-08-19nXCIxHXcUs.exeexe cd96a3b4b9b993884d39900a556378fde2140de8770828c1d6d31b5e966edd3fn/a Heodo
2020-08-19UC8iE.exeexe 48e49748f46bc7e2b52fe87f4db61df4d496b87ccb3fa7220c1e9622fd4ecafan/a Heodo
2020-08-19kbd41.exeexe e5aa4c043753f2f0c501810f3945794f0a3279339f94180690c800128a51d8a5n/a Heodo
2020-08-19ITo6.exeexe 6fcee04694a7f06974977d073a4740b4e6e729e7a3a24bd29f4b15d7b3ad0329n/a Heodo