URLhaus Database

You are currently viewing the URLhaus database entry for http://sindicatodeseguridad.com/_borders/lXe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451196
URL: http://sindicatodeseguridad.com/_borders/lXe/
URL Status:Offline
Host: sindicatodeseguridad.com
Date added:2020-09-01 15:47:04 UTC
Last online:2020-09-02 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-01 15:48:11 UTC to abuse{at}strato[dot]de)
Takedown time:16 hours, 57 minutes Good (down since 2020-09-02 08:45:38 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-02juqP.exeexe 6dd5d673725341b0790fa4f3bed96e49d656118994b0b19c38e62fd53defb39dVirustotal results 14.49%Heodo
2020-09-02x00mAYyJqYE.exeexe 598bea746526d6eae854e126eac4b4b22e1023363875c53142ef4b05491fdcb2Virustotal results 7.46%Heodo
2020-09-01gyr.exeexe b6f2457e50dc2fdd2cf809ebf63577c7277e0e26bf8e87188572c01d96d48f97Virustotal results 7.35%Heodo
2020-09-010hPPOn75SS.exeexe fb13df8b0a039ba2084a3a5e4214347716b56fdbd7f3c708717bb439acce3656Virustotal results 20.29%Heodo
2020-09-01LT71GPDCzQp1ujNyqe.exeexe ffba4a10303ceeb6c2646d55ca53f851b534cda19745669e867da32f973c914bn/a Heodo
2020-09-01ROkQNWaGa2VyE.exeexe 87cf6554d017b0417e6d07d0d8a47ce0cad3c51d2c48113a3d78f4d7e2e788b6Virustotal results 11.43% Heodo
2020-09-01roJ.exeexe ed86718231cbfec9d342413220886bdaecb6d244f785f6ba74f95c390b64bc3bVirustotal results 11.76% Heodo
2020-09-01EkL6xboOG.exeexe 5e8a76036ba57e6fae572b87e2d25bc23adf353e43941f280084a08cc2350bbbn/a Heodo
2020-09-01zCGTbN.exeexe 33392ce5d312b45f2655ed38c035d2160849899016e58f123963375a83bdb172n/a Heodo
2020-09-01gR8PQ8Oq5Tka7.exeexe 57eccf48b552988a96718fa29587503a5a1f2a974df3ea80791c54d7ae8f1ea0Virustotal results 11.59% Heodo
2020-09-013KbCg1.exeexe d88602d45f291e88d42831f90e7912d14c2e95f4644def9a2b8794b8b432e0f3n/a Heodo
2020-09-01JcGQSA2Q.exeexe dcb107abaf207447fd99bbb8d42918210457530fa92ef0d01834812cc10de7a7n/a Heodo
2020-09-0172zWOywZgENj.exeexe 08eae073ab4bd0339e04c32aee04a545a3e0b123e764b6a3a44d0e9139946469n/a Heodo
2020-09-01yylVvDW79zNS.exeexe 8aa3723894a33330d7486ef74a0c17f7821baae6dd53d5c1a4f498c49d025b9fn/a Heodo
2020-09-013Ks0CEfHcNt.exeexe 92da585c59d174c4845a2fb307a32f3bdf0aa6bdcc09cc599eae9d9cc83f5275n/a Heodo