URLhaus Database

You are currently viewing the URLhaus database entry for http://wetzi.de/cgi-bin/file/heLeDqESyV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451217
URL: http://wetzi.de/cgi-bin/file/heLeDqESyV/
URL Status:Offline
Host: wetzi.de
Date added:2020-09-01 16:19:06 UTC
Last online:2020-09-03 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-01 16:20:08 UTC to abuse{at}strato[dot]de)
Takedown time:1 day, 18 hours, 9 minutes Poor (down since 2020-09-03 10:29:42 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03000120285112.exeexe 69459a47918ed6baeb6ec093af8fb6c209c99d2a7c4c1fa5a7b4584d3bac9276n/a Heodo
2020-09-03ZIPNd3Gb63329004176.exeexe 10a9dcb33f17cb30a89eea624e23770febe9627693414d8daa5c0048b840f459n/a Heodo
2020-09-0364867068379.exeexe 97e9868cc7a7cb565a9ca53e59d2357b8cef0408c94ac56cde605ff83930afacn/a Heodo
2020-09-03000042XC8A.exeexe b43c889c759f99c521d2cc4f0b26d02e3446a12586884c190a15c77a0755e276n/a Heodo
2020-09-0384BzV07tn.exeexe b8f06c49beec5ebc8ac0dd57e68e3adb513c0778139dea01026d7235919638f8n/a Heodo
2020-09-03l01geBOLw6B.exeexe b006e61fcdb6053bc4b6d5e3892769626fde62895f6d2a0784aeaee4a557af03n/a Heodo
2020-09-030081108797.exeexe 77b7e0e1fc23f23141c42e42f9aa4f222f4a632dcd08989f146966d1ac7cb90bn/a Heodo
2020-09-03bbSvu5p772xk00082633723.exeexe d335d3f4e14387feabfdc8f6ed4bc9149101123de66c91afef08fec9da6681acn/a Heodo
2020-09-030000645498077417.exeexe 0e7e5cbb1369c3f2dabc5db7f36062f67397655daf9fe6b12b3f0e1549911f07n/a Heodo
2020-09-03wN49927812.exeexe e96b9086ee86ea96abbdd33173cec3e3b1429501e4c2d7f8da20507fa1fe0ae2n/a Heodo
2020-09-03041635907QNm8k.exeexe 7ad85c0fa09617fd5116bb0dee31627892e51bc5a0be0f5830e52fec08c33facn/a Heodo
2020-09-0338115549.exeexe e129e91f3a02d857439b32811b77a9c9d08304253e41c8a8aa3b02fba1e2dbe0n/a Heodo
2020-09-030Khx407797591210.exeexe 6512e0035cf2688f1c380cd9dd4c079c223aaec33d3abb7e6e5d867e430e59c7n/a Heodo
2020-09-03yMsL5.exeexe 25b2a2219d08b123e058682943a9c18857b949bf8fff9c0b784464f3ad16608cn/a Heodo
2020-09-03l6Dt00506508291.exeexe abb879ec5aad858237f3b3fc52ba107a4ef79ba99297f0d3f580e52e9a79d777Virustotal results 8.70% Heodo
2020-09-03xYEgp5262351276.exeexe 3cd5f8a162cb5445a4799dc72652fac4aa06aeeda44e27ef780325b08be94724Virustotal results 10.29% Heodo
2020-09-03tZn7cLptNp5A.exeexe 61e84830a763e77fac009738f364e2b48100d854f25d7ccb63864b77503322e3Virustotal results 8.96% Heodo
2020-09-0300554pArA0wvYw181.exeexe c7be8124974d949e6d0fa664c4fd1ceafc2d5671a60d2d33dfdd83415264080cn/a Heodo
2020-09-030059299248rgi.exeexe f7f9312aa253f7e355e48750f3dd2f45c9811b0a161f9402a9342b61f8f9f7c5n/a Heodo
2020-09-03cjeoYD.exeexe 44e79c6ac38fca4ec4fe2144d2c2b97610e7181bb172aa13ef96499dcc516b56n/a Heodo
2020-09-0300001.exeexe c0581ba04e3e1543f160970669e6d7bc47607ee12dc06c257232b10d42ae8b40n/a Heodo
2020-09-030000977011.exeexe 60b1bff3b746fd606bc55b146f99dbab6baffbfc3ed7468d04496b99dba975bfn/a Heodo
2020-09-03zZTu6aikjlN.exeexe 2a7b21a98bb18de2b554125bd73b40d377de01724f061c5ecb9384bdca6a0329n/a Heodo
2020-09-03000060846400578C8ZW8ezE.exeexe 7b859c33f54e4995b856bb170f973f7b18211e560979f87c4c5c54842e7fb669Virustotal results 33.33% Heodo
2020-09-03haYaFGA2bOF24.exeexe d66b7d1437475b76936cf05aca53bfa47a9132ce9302ea86294b93fd70bca0a0Virustotal results 34.29% Heodo
2020-09-030IjZ9aWze918324.exeexe 993cf8ee7679f03a5defb5ac3f2a394bcad058205e9df2d49fb2a9e56efaa18en/a Heodo
2020-09-03003439udMnnu.exeexe b746cf1a6b0f8ab8c975b8e31f98e3eb46567dbb512ec9aaa88f794cd34fcde0n/a Heodo
2020-09-030000524907260.exeexe 568b445e58002048fc1f4d27c50432c48b6d4766b3705d3bcb6842eaf29a4c07Virustotal results 32.35% Heodo
2020-09-0300055604367.exeexe 759a6012ed4a70a9959aa2d3707414fafddfb3afe8fe0368d8d88f540052f072Virustotal results 32.35% Heodo
2020-09-03DHRQwb92218.exeexe f1a8e80e73f04437d89b781b8d8a73e472ba1e93ef83e081fd3f2135748a8ca1n/a Heodo
2020-09-03rh.exeexe d0a23366e598c9ee23b20f3e678b901a2c6441391f80be4806d3cde10b9167fbn/a Heodo
2020-09-030009059583938.exeexe f6a7dcb13b5ef109788f09800abb0c7be9733b5125f2102e6bd52a2a6c05c528n/a Heodo
2020-09-03D7000363150326369.exeexe e8f99c4814da58c8fecbe6e05a921f048bc562ec8e4760d0b376ac68aac37331n/a Heodo
2020-09-0300000.exeexe 8ac91bb7cd20190386e52f8fe75832bc4c7853ccbbd370e9f35416fe33b01ed1n/a Heodo
2020-09-03KJ.exeexe 204211d700cc6282b8686aca40b40aac3e1a827f9a32ee5e734b9a38c2dcee6fn/a Heodo
2020-09-03nFY8468245.exeexe adda22f767a33408b699296ee3f51f1e920bcd7f6f66b4cc95e956f8217d2cf2Virustotal results 30.88% Heodo
2020-09-0300009.exeexe d94efeeefabfc19ad610818e516df036f48d5d6340bc1cd510b3c95af9876408n/a Heodo
2020-09-03aDwO8bhEgc000307968192466.exeexe 4b727149eeabfabf747df06b7fd40cb143e128754c513d1cfe78bcf432834412n/a Heodo
2020-09-03dSVR7WE.exeexe f71fe3cfff03adcef2171526bb9cd72347868547b97555c7b7d1f641a61aefb9n/aHeodo
2020-09-020000273694730hKTE.exeexe d3fbfb2fff96c99ae3d4ec29d9e487a34394b6f2484e2dd18815cfb5f0a7b010n/a Heodo
2020-09-02ICSYI00493.exeexe 9f304462280dd0ed60b80f20777f078cf8e21ad98b1544c36e09b3db04d5d592n/a Heodo
2020-09-02rsINjfDKBQ.exeexe 5be286d358dfcef691b3305d83aa5dc57457217befdb7bd88728335e96ec4dadn/a Heodo
2020-09-0200062429502UUUb1.exeexe f126db7c9785da343be1aa0293c46d39b16e615d1c19499f918c5fb29571e0ean/a Heodo
2020-09-02lVohdyIpVO.exeexe 9d598f295a6cff7f3a6f92e2293b76c37e0f56e2800ddf584276c7859146df0cn/a Heodo
2020-09-02025BO.exeexe 537a92c4a9757373f1a45c30d0e1e2fba427b5acd575ba7ea8787bfcfa619209Virustotal results 26.09% Heodo
2020-09-02000096698sa.exeexe 3c824b9ef64cc637491ff81e4e6bf18df5d879a8c57e72129c1794ab12f0e1bcn/a Heodo
2020-09-02125180684.exeexe 5de3306ddeec8264c76615a854482439527b46f3c166f9978ba198c7e23332d1n/a Heodo
2020-09-025408359122204.exeexe 6aaf31eeabf3bd26100a46b490838d8448eeab7e0227a349d86754b1baa20f9aVirustotal results 21.43% Heodo
2020-09-02Vea7WH85810779.exeexe a2c1305f9312018c8bedc52407e18d2aaa193e6824ca4610be2f0e4e4e4e9314n/a Heodo
2020-09-02020025562604.exeexe 3d2ea7bfa47c6a441c82d0d2fb86355f49531ed9e693a0e5cd24974d69c3e5c9n/a Heodo
2020-09-02002638.exeexe 21ce5bfe213ac5114e41e3b29db20ada078a6428572c5319f1bd653f66150fb6n/a Heodo
2020-09-02631008568.exeexe b22db75720f0af22879fa05b0400442edb770c6b5c304aa48833d0abb9d789c8n/a Heodo
2020-09-02003562047.exeexe eb1a2e703502ec9d81d748cdba9d8c3d0b018d00ad90399e2fdbafb2132dd19cn/a Heodo
2020-09-020000948799028238.exeexe d5c3c61493036696d599ba2ad8611911a16da273c187b319cbbbefb5de89e5afVirustotal results 14.29% Heodo
2020-09-02meqSRXW00093001729.exeexe 4b8449e849c00d091a2ac5a7da7a25a5c0945887d24abaafc9c46e8bb0f7a734Virustotal results 14.29% Heodo
2020-09-0252500232yLPE.exeexe d29e6ff40f2d1e524ace6c6b019d918e46a754f275212ca72f1ad16ef3d5d267n/a Heodo
2020-09-0206ET4EC.exeexe 097a118cf9ceac8706ba5c9bb50c5fb681180f79d2ac6320591095542aa2cfb2n/a Heodo
2020-09-02000734mXHuQw7ESDH.exeexe 407cd5b8c2a45734cf7a07d114dde71c3b9287135acd5b31d3269b417353499bn/a Heodo
2020-09-02AUuSsGEHz7860043.exeexe 901e63321a2a873cbc3c00b79e98be86c7cdd5547cd3ba78d5f066570a57c93en/a Heodo
2020-09-02u2NxjZcRhQX07533118432402.exeexe 68e0325cdb09a8b85821b5b2929782984623b61d9bd9014570cfa4ea7ac7525fn/a Heodo
2020-09-0200075L4W.exeexe 2ea269388925bacae7bb793055611064af1db1926ad4519c6aef2add66ec0fa0n/a Heodo
2020-09-020128479610965.exeexe ec5107b5414cb461be216449e2ba324c62369059b7f85f3ade962d1170b2fe18n/a Heodo
2020-09-028DkNhN.exeexe 853dccbd8732bd693fd35cd58171ed6f14eca46982c127564b76c60ba86f0d14n/a Heodo
2020-09-029725116gRJp.exeexe 3082016d9e35e853e451e654689eb4fee6a4061955f098141d8f0d843103e63dn/a Heodo
2020-09-02FBKk1I7vTlEb.exeexe d7b2faacbf77a440d2cd456940be09d308cfdc6bb2b26dea698c3c0c65912c09n/a Heodo
2020-09-02T800000413418.exeexe 05b58bec5deb24ff95a10f3a91443ccd6178141ecb33c564290367cda72680b8n/a Heodo
2020-09-02oVPXbHH2CDT.exeexe 76b1866bc259e3c64671a52d3a4a0e584eefe57b275cf830aa7096c47f91cfc3Virustotal results 10.00% Heodo
2020-09-02000449285034.exeexe 5699df8f5be1e4b3af3c5fe865ce41dcf8a65f7bd5d0dadad53a8427b059bca3n/a Heodo
2020-09-0208C4hVcoKUz7.exeexe 209557e5ef633ff696b6ea36dc0380913d841b11c754faeb2bf41c8f602decdcn/a Heodo
2020-09-02RfP2uZRx6.exeexe 3831a47456036a4e8ec5420ba4d73d728c38dbe65a148503f36fe8a0a7bdad2dn/a Heodo
2020-09-0200040098.exeexe 0424d0b57697a7b88e1be54ff8245853dff3a2a8f34d61cdf10e333af677de74n/a Heodo
2020-09-02VfMIy0886221.exeexe 21153a8bcb9e592f726debf19ce3a7b81546fc59360195758d2eb0fffe760b96n/a Heodo
2020-09-02000059691034h3YNshD.exeexe 15cb49ab792aec0a7b5ecba98d38104a56962fc48b6e38a8920e1be7b38f382fVirustotal results 14.93% Heodo
2020-09-025QGSd57fn.exeexe 70c47e7da37d04e4df30237367c7bdd8e49dcb824da4b5bf5d11b3326904de45n/a Heodo
2020-09-020057779620349e.exeexe b62517d1931209dbcb424960e61a82c8c0f38b05da1b8601055f05b42316505an/a Heodo
2020-09-02WsxxVD30oU6I523053515.exeexe 849d2fd16423d8a18db0fb9a24cb684574a536ec3aa087ada02e6d1267b2ab78Virustotal results 13.43% Heodo
2020-09-022p000687681.exeexe 1f5947b97f406920e719e6df844473fc411ad8def4f2c7cc9bdaec4e8a7e5159n/a Heodo
2020-09-02HHdPZFSxazn.exeexe c0a7774d52aa8d155f42cbe92ced0403bb3490ae33fdd016700e10693470f1c0n/a Heodo
2020-09-02000573453.exeexe 1c0bbb1d6915b545a47c1c595135d6e64ad0c392f91372631fd6c3bc3a8bcf91n/a Heodo
2020-09-0251Of3oryqf1J4501.exeexe 98c914624e239a210547642addb1c133dc546935b10cb4fc3de1ead4d6cdfd34n/a Heodo
2020-09-020273563.exeexe ee5ca11db4411f9797c62377820111a29f1799ba96203b9bcd36b241a8c0615fn/a Heodo
2020-09-02IKE0qjvkwfM0036721833.exeexe 26ebd8988c919b45db6c3beaccc4b56153431eb7cf8092d2672d1d1e10acb4can/a Heodo
2020-09-02VQXIpIcURKl0833816236729.exeexe aa219aedb9e969b210392214ff58e291cece91c21235b7bdd38b4baf6d49a7f6n/a Heodo
2020-09-02029.exeexe c823b2e3758ca50c21058c7de49269b7d868f176b110aedb13f9b020ef601415n/a Heodo
2020-09-02F5000958956.exeexe 472166979aac1ac63be65a425d7364dca6c117372b0c10d09463dbd9dad7a7cen/a Heodo
2020-09-02000198161.exeexe 23f95306085cdc5202ae455003fee10d5752dd650d6ff71a7b2d016d7db7e2ffn/a Heodo
2020-09-02033.exeexe 8957023c7cc29fec139a15e2c287edd328680d0516aee7bafce0023d6be27c7aVirustotal results 8.70% Heodo
2020-09-02epr4906517706076.exeexe e2058674705b18243e1c8b56f47683913f8cd17738a62cf640e38eed825a21c7Virustotal results 10.45% Heodo
2020-09-02PEMPzhISunt53.exeexe a378e5beb74d9591d2bb4dfde9ab1f0c84c37f2876f753070edf7c6da560c5ceVirustotal results 7.35% Heodo
2020-09-02000855445403856L.exeexe 3892fa7343bcc5c4819772d794e1d3e7e1a7932494d07e83c777ae105f635943Virustotal results 8.82% Heodo
2020-09-02hXc000014659549424.exeexe bd3dc4657de66d33ce2f2cac43529cef3d5da66258c992cb8d9674f957e84473Virustotal results 16.18%Heodo
2020-09-025007112227.exeexe b6c7c65fcf04c8cbc8b9be5e4e6cc6948239df9bacd6230d5a22a341e5066c9dVirustotal results 7.35%Heodo
2020-09-0100077651.exeexe b9cae66117965dd38dbce964d87c11899129e576754f98af23af9f8d7e6266c7Virustotal results 7.94%Heodo
2020-09-01bo2bhGxwdAt00091321998495.exeexe 43f9eacf99a6289eb8d428ae5ad0af1b0964f13c84b562de78ef47b8d6591ca5Virustotal results 17.39%Heodo
2020-09-01412180199.exeexe d632ebb664af916695fbc4d4efc9ccfb1b02ad017826827097329d533f2263e2Virustotal results 11.76% Heodo
2020-09-01jVLLgG60.exeexe 65ee2a011e93d237e80a4a04b0b561ae0bb4c6e48a60a44af5b368b5df730833n/a Heodo
2020-09-0100074091691.exeexe 40a8fcabdd48e76b02b6a117b7e08b7f321f2d1e233d1a3d6449aaa1565ac0f1Virustotal results 13.04% Heodo
2020-09-01007283944479K56tkn3HYOZ3.exeexe 8ade094c7a91b0a597360a0d0e501cf6123ec13a4603a857426ae5bcccb018d3n/a Heodo
2020-09-01kJAY935764244.exeexe 270d4a7246e64216c5005be5b9cdbb599f2e3b21fa92641755ffa73fe74795cdn/a Heodo
2020-09-01ALMqtK6nSq8v633215.exeexe 0f4a9856741eeb0067f76bc1aad1095686114120292e2437d1bfc7b41e0c966an/a Heodo
2020-09-010250116.exeexe 2e5188011fd4f615dce8245437698f249d99393e7fa0ff42785ff9d71aa68d81n/a Heodo
2020-09-01xXiE39.exeexe 691462f02838fbccc69f82450b1c5161cbd6e84d99f41a28964617f8380e5ce2Virustotal results 13.04% Heodo
2020-09-01Wm07.exeexe a80192a37406588b55e67b20dc0aa29525026ccd39678412430c74a667f7a080n/a Heodo