URLhaus Database

You are currently viewing the URLhaus database entry for http://www.emmashop.sk/sitemap/f00nsf09254466/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436741
URL: http://www.emmashop.sk/sitemap/f00nsf09254466/
URL Status:Offline
Host: www.emmashop.sk
Date added:2020-08-19 17:27:25 UTC
Last online:2020-08-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 17:28:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 16 minutes Good (down since 2020-08-19 20:44:56 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19l9ke205944.exeexe 6a68cbf125f4089eb5f45250d756ccbcb1f47e6bd48b86406c8494f435185545n/a Heodo
2020-08-19sh8c00009923719969.exeexe d3e2d9038ab0db6c0a9f0e35c7e43716475975997297e00e443509afd7ace091n/a Heodo
2020-08-19cge89164340.exeexe 23c05f0139c20f6de6dc915efd98655b41beaea75b56ffbb7925118cabaef83fn/a Heodo
2020-08-196q2ssbg600523324.exeexe 6e96a6f9a65adecbe80f1b32e57cc3990afdd8deaa0d55401251e057441e2285n/aHeodo
2020-08-196zbaoiw007026.exeexe c04f161df638e846eac86b668338cf1532ddae7fe9617a374eb1e74cc080b515n/a Heodo
2020-08-194kdx0059743.exeexe f4511bd09afcb2e13a0fe6d03828e63ab73b88926e4aca742bf0a8d58592ea41n/a Heodo
2020-08-19oixwdr0065.exeexe 8436e5233e7e70c411aa178a5358def7dd49e10885c915e6b48d4bdab8e10dd3n/a Heodo
2020-08-19hhaw1ke8m9c675113763.exeexe 7465f2c7c35363a99771d78e35c13f5cfa01064baff745cb57359e5f75a61046n/a Heodo
2020-08-19j25p4lj80008.exeexe ae2dabdbcb20d30f9dac359f4a3850a604a37009217b344827de5c3f75c5d2ddn/a Heodo
2020-08-19xc0000072041.exeexe 721cf4e5237b36b1341a4bc9af60a1bdb948af57d87a3db3b54ba74ed2f40bb3n/a Heodo
2020-08-19dktdgpdb00003680775219575.exeexe 45624160f8e653dd7d2204ec54cc83f3a3e8bca907008bb79948522c838a00a8n/a Heodo
2020-08-19ptxoagtn137966.exeexe 3722372e09992bc6486cbe9430171a4f71cfd3c414cf50cb73f8f59653641955n/a Heodo