URLhaus Database

You are currently viewing the URLhaus database entry for http://centralaviationsolutions.com/browse/N3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438260
URL: http://centralaviationsolutions.com/browse/N3/
URL Status:Offline
Host: centralaviationsolutions.com
Date added:2020-08-21 14:10:39 UTC
Last online:2020-08-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 14:12:10 UTC to abuse{at}dreamhost[dot]com)
Takedown time:3 hours, 48 minutes Good (down since 2020-08-21 18:01:06 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-211nVo.exeexe 4af2b472efd8369d5525586d1465593c74943eb74d899367607cdea17d5b7444n/a Heodo
2020-08-21CFKAiT1p4aoCJEHKZtKN.exeexe 26a0b867dc9b259dccdf06c61cdefc599325214e6cef609be85060d935364837n/a Heodo
2020-08-21HaNKc.exeexe 9233f61e279a0f0dca28c57fa8ead5fb9bc96d544f436b1a9102b70959aa9485n/a Heodo
2020-08-21DokWYOk3.exeexe 0695763e2446a8711e02813dbfd6c527838b08ba923c0b23dffc2e3d299d4daan/a Heodo
2020-08-21YBw.exeexe ddc4f07e58e78385fe84a02988d1ea56993c42fad519a6ffebeb5d024dd750edn/a Heodo
2020-08-2144tg.exeexe 190a4c3069c25945affb8241f35f6efdb2495ceadc369c37dd08b71779794ec1n/a Heodo
2020-08-210F0yzl0bpTkVSi.exeexe 88276fb4bdd139f5a832eb5092f4c419ed129b4f649d04676317c3a98d03f24bn/a Heodo