URLhaus Database

You are currently viewing the URLhaus database entry for https://itisfuture.com/wp-content/Zg21h52700782/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440585
URL: https://itisfuture.com/wp-content/Zg21h52700782/
URL Status:Offline
Host: itisfuture.com
Date added:2020-08-24 23:45:24 UTC
Last online:2020-08-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-24 23:46:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 45 minutes Good (down since 2020-08-25 02:31:15 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-25ZD21.exeexe 178d59b0a6490b03b4f653078cee295d61ab9d96df1d8029def2e30c9b510953n/a Heodo
2020-08-250QFKzNw800008974361.exeexe e0aea2d123643da1430b9627ad238bb2e15d90920bae571475f28656e98546d8n/a Heodo
2020-08-252e004639383.exeexe 8c0ae98b37b9b381d7e8ac0bc94fb278a0ef201c8852ac6a2a9a363428f73f56n/a Heodo
2020-08-25rli00005047.exeexe f82c8844c9a9e086e3d4912af72c170d5d53519b3142479a3bc8e614d6ce73c3n/a Heodo
2020-08-254ofY6748809581.exeexe 86e4d6d4bf4a0f99b25b8b3a4dcd8dfce24f824d4463184b918410e4f32ccf9an/a Heodo
2020-08-25C9OO8ry00084603611974.exeexe 837e08c5cb0651b1eceb55ea5246f6801c02a9e40628d5e73ccf8865e639bdc9n/a Heodo
2020-08-25zPCVh9hosf0000744573.exeexe 666e438828f13b19bc6ffe583df68e8b06795ec781e27b04eefae6f3fc419613Virustotal results 7.25% 
2020-08-24syyGu85U56Nh0006390130.exeexe 8ca2a4f983d7aef8a69bc408a2fa25b3a3715506a6e50afb710dab7e08189d89n/a Heodo
2020-08-24tTX3984729.exeexe eef131cb3aa270f68d0343c3aeb7bc498e1f00b7128cdfee282ad848be0ce682n/a Heodo