URLhaus Database

You are currently viewing the URLhaus database entry for http://rootsroundup.com/css/98Y1F8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438462
URL: http://rootsroundup.com/css/98Y1F8/
URL Status:Offline
Host: rootsroundup.com
Date added:2020-08-21 19:09:12 UTC
Last online:2020-08-21 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 19:10:03 UTC to abuse{at}idig[dot]net)
Takedown time:3 hours, 48 minutes Good (down since 2020-08-21 22:58:13 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21ImpiNzzD.exeexe 70ce80d58112934c5f9e03fdaf3a42dba20a3ba16f17d332efff53396f4b6d0en/a Heodo
2020-08-21HzRAq.exeexe 54feeb403f71849324693eb741542c36548065d33c7223303d8c6c8b3ccd1c2fn/a Heodo
2020-08-21fzsYjsMMn4lEs.exeexe 939328d902a6e7fcc717832636b6d12f13e4e8c003740075d70eec54f288e433n/a Heodo
2020-08-215q.exeexe c7f13a12d642a5b98f68687bcc5ca29eaf9bc5f423ee10763bd33aeac2b4e678n/a Heodo
2020-08-21d1q0AZujgbuQv.exeexe f3aec131bc95895b56c57c87d89b7d37920a699771ade9f0b8a73e63e15c2052n/a Heodo
2020-08-21vFaVPXhtXWxKzEt.exeexe 8db32cafb770c3e286c40de9dde63a713608528197f67ef0cc1a0b7918df6e10n/a Heodo
2020-08-21CEPzaBxk9.exeexe a45a35980f8d3c62f6874b6dc49d925d52d1e6c8c2d8b138ed0019781c4fb63fn/a Heodo
2020-08-21exyJf7R8J4iWSTDE.exeexe b824a2f857b3bc29e6550fe835129c8d894c5d644677ff4b8a9624116e5c0925n/a Heodo