URLhaus Database

You are currently viewing the URLhaus database entry for http://tjdengler.info/cgi-bin/r/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451194
URL: http://tjdengler.info/cgi-bin/r/
URL Status:Offline
Host: tjdengler.info
Date added:2020-09-01 15:47:04 UTC
Last online:2020-09-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-01 15:48:08 UTC to abuse{at}strato[dot]de)
Takedown time:17 hours, 45 minutes Good (down since 2020-09-02 09:33:08 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-02ZoknTp.exeexe 6dd5d673725341b0790fa4f3bed96e49d656118994b0b19c38e62fd53defb39dVirustotal results 14.49%Heodo
2020-09-02jY6gTSGFwn.exeexe 598bea746526d6eae854e126eac4b4b22e1023363875c53142ef4b05491fdcb2Virustotal results 7.46%Heodo
2020-09-01TLS.exeexe b6f2457e50dc2fdd2cf809ebf63577c7277e0e26bf8e87188572c01d96d48f97Virustotal results 7.35%Heodo
2020-09-011yHoB44gxEI1uSY6H8Wk.exeexe fb13df8b0a039ba2084a3a5e4214347716b56fdbd7f3c708717bb439acce3656Virustotal results 20.29%Heodo
2020-09-017hkeTtxxA0v.exeexe cacf14db3d7287af50072ffc5c15bcb6f7e9df4295bad534b80e5b679d0ff766n/a Heodo
2020-09-01QMyggGSlyyWU2KqBifv.exeexe 48197eb606cbec61d55f47ba76318e16469455f0e22066d9812a06b46624f500Virustotal results 11.43% Heodo
2020-09-01ccUMgiybddDU5rk8vCQ.exeexe 20f412f847cc558eb87e9c0e52ffe201132ad73151b176fa185925387f3a46e5n/a Heodo
2020-09-016NwpXwAM0wzH.exeexe 8914e4d40adb380643d8b294a81a1a11bbf834a3f1752bcb75cd044e0a2a953an/a Heodo
2020-09-01kfAeti.exeexe e7ca058e6d51026d628499c03da1282be457c6d6298503867f487f500ab0b24en/a Heodo
2020-09-0123Z4ptlIKtG3Ds0rWX.exeexe 02903f53fd469fcff84b7727f0b5d007d2b4d0aa2b9f3d0366659b97dce47545n/a Heodo
2020-09-016t9b3rgpr6RbqZ.exeexe 3b1e374b7a03d514421e99e23022a5b8f3b3f1e4e474c8640711b50e6f469fedn/a Heodo
2020-09-01dpCc1TsHqyYXr6K8.exeexe a097cfa8844b7663263c23f9138af59be55b5925e104641f441488fbb3a74c55Virustotal results 11.59% Heodo
2020-09-01hAkiv9ZWu4w43AyUCC.exeexe 321b42b24ec5dea8df2a7a1297373d693e5213af3288184118280359b7eda23aVirustotal results 10.45% Heodo
2020-09-01KwBCzj.exeexe c2cdc4e3d229986a2f8ec05f8e3a7365f30a904ef320f1a005b80f1d02a737een/a Heodo
2020-09-01h7PJIs.exeexe 9412070a444957daa434c15d5c4a6b8397405ee0135d67776de0faae8dbc35b5n/a Heodo