URLhaus Database

You are currently viewing the URLhaus database entry for http://techlh.com/list/f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444388
URL: http://techlh.com/list/f/
URL Status:Offline
Host: techlh.com
Date added:2020-08-26 12:38:36 UTC
Last online:2020-08-27 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-26 12:40:05 UTC to abuse{at}kgix[dot]com)
Takedown time:11 hours, 51 minutes Good (down since 2020-08-27 00:31:24 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26CLrUk4a.exeexe 01062f289507a4659a2c237c4898c35f3bb830816da0c0f1aad77688c51b266an/a Heodo
2020-08-26fWxLpW8u8z15l.exeexe 7322f49b806118eda6f4df61a8c99128024cf94224060fba6951c63e21c1cbd1n/a Heodo
2020-08-26rv6etmWZrmNBynM.exeexe 53bfb06a44ef7f5b0f710a532d4825343be13c953cc99d2ed7a59e374e4edba3n/a Heodo
2020-08-26TQ1LcIhtwSAoIw5sl9.exeexe 2947f318cc23516c6bb116fa69022681e685875cca87ce75b4f1850719d4d3d0n/a Heodo
2020-08-262G8hjMeAgzq.exeexe 10fedbaa939ad6e727857fab890cd3fbd7754b1e9d2035d4a53e2862c346118en/a Heodo
2020-08-26ttbsNsn.exeexe 09254fec6ba0db62872a028cbe9e149540d18652ffe86cdf8f1796b829a5184bn/a Heodo
2020-08-26Z4LQmjCa.exeexe 88bcae87df18f15927a8b37f647af48fa26c2277bbdcbdc5ff1f0d005a19e746n/a Heodo
2020-08-263D05HdftCVYBiIL53AS.exeexe 3545ab08e67a59c747d5402e2a01da90cf1d711ec2037a42e074be391241a1d2n/a Heodo
2020-08-26vnBBy7KbEDkXyQnsfwWl.exeexe c2d892972eceacbbf429b9eb6f24537e3bbabcb25901342b6f0739592f8299f4n/a Heodo
2020-08-26o57wWvm01yPfMDcAeaX2.exeexe 8adc3271906ea07f3b7dadff10bd0c26c694bb1d38060e8582d9f3e03c73f446n/a Heodo
2020-08-26YY9q7XNj55945J09.exeexe 5078168293358f9fcab979f3ff5e1ac7b586dc065d757fbcc148c87e87d0726bVirustotal results 11.59% Heodo
2020-08-26bbfRU1I.exeexe 0c0591c015d78e1b810592655904f48589bbd3372743e9e8c1fe74ca9b660852Virustotal results 11.59% Heodo
2020-08-265hTtPKjE9PkX6TWL6n.exeexe 05be4ab76310e8a895b26c37f97ad526024e18872b23f4ccba969e7cb78a4f78n/a Heodo
2020-08-26uhtpNfSm7FIC4.exeexe cdaa245af56f6b6368c4d8682b810a2f9221c09e4ae1ef06061a2d930b56cf84n/a Heodo
2020-08-26MxK4qFJ65zqyi.exeexe f20f8c2b900c4012f2ff67b46a68d4bdbb483bfc74fbc58803165304537fa34cn/a Heodo
2020-08-26GONnAT.exeexe 420de11fde0be09a559ff3b3545bd1e19ae9d59ae601f0decc20e0d31292fde5Virustotal results 14.71% Heodo
2020-08-26LamNNxp4b.exeexe 69e79898094fb280631e0d64257b8e138a519eb1952e6dbae3c58127560b9054Virustotal results 13.24% Heodo
2020-08-26xiLKXAeu.exeexe ec8a1f2c9cdabb3db95f227353a206079bc1d637baf8892d1067af56cea8f775n/a Heodo
2020-08-26bjv7BE6.exeexe 80fd110d711826b0dac6da9ffee4d1ecd1d45fb6a73791987f2e4d3f7a91b4e7n/a Heodo
2020-08-264NQD.exeexe 15a993bfca1ffe22eed56df4a8c08f3378a35c6500508c35afab4eaffe645e70Virustotal results 8.70% Heodo
2020-08-26MDy0w7GRfRht.exeexe d0bef5acf40de8db7c1ea1ae47da0743f0dda5ff6f03028da0103ace417d8c0cn/a Heodo
2020-08-26rqqalueNVUzTBu8HY2cU.exeexe e3b9ccf9f49b073a911620f403d9e329bc7da72ca9c35596c9b52565c77bbcc7n/a Heodo
2020-08-26ZlEMQ.exeexe dfd93e3bef48dcff1df0d0b6412b5afeb80f9ef20bce8111c037e8929fea914cVirustotal results 11.43% Heodo
2020-08-26KECJMTaLLIhwMBOVL.exeexe 429b360932ef53ce79a4c11fbb41237ba4054cc52db2854479d6804b041302fbn/a Heodo