URLhaus Database

You are currently viewing the URLhaus database entry for http://propertywatch.ng/alfacgiapi/K5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445096
URL: http://propertywatch.ng/alfacgiapi/K5/
URL Status:Offline
Host: propertywatch.ng
Date added:2020-08-27 09:10:08 UTC
Last online:2020-08-27 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-27 09:12:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 17 minutes Good (down since 2020-08-27 11:29:09 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27BFJlCc4rurnSEQg.exeexe a1e7a9cbccaf404d5621153de92f835f775aee902547d6d3d7176893a125b3dan/a Heodo
2020-08-27ZQ4TEaoQobm.exeexe 27164cb1765c114f934420a230a170fa41497deab5ab7022743fe581ba6a12d6Virustotal results 8.82% Heodo
2020-08-27MiWJiPQkJy2TZv8.exeexe 36a224ad78379e84773106929b4048bd5348f7678cf30a8430e1b6c08078ad1fn/a Heodo
2020-08-273i.exeexe 9e5f21e8554671bcdcfefbbd27873da43ee54f7877e128a240fcc3ca82a9b35an/a Heodo
2020-08-279oJuSXGHzeLD4.exeexe c94324b09c63df9d2af2fb9917b3c5d71cf384413cd60f6a0aa009202db656d2n/a Heodo
2020-08-27yLAbcvYDCRWv7awpiA.exeexe 1d3224d281fe89cbf6ab033346e9400705ddba42e4d57b8fd73cecc2b8ccc068n/a Heodo
2020-08-27bBKaExxLQiqER3us3.exeexe e020412b3a130f03210183c227c04b70b268858362c70e332df0604d504be61fn/a Heodo