URLhaus Database

You are currently viewing the URLhaus database entry for http://relicatessen.com/index_htm_files/9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451268
URL: http://relicatessen.com/index_htm_files/9/
URL Status:Offline
Host: relicatessen.com
Date added:2020-09-01 18:17:04 UTC
Last online:2020-09-07 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-01 18:18:08 UTC to abuse{at}arsys[dot]es)
Takedown time:5 days, 9 hours, 19 minutes Bad (down since 2020-09-07 03:37:27 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03kesop95aXgnYVcHvR.exeexe c5c4338aea3b1577fe7bfeaab139da4821f8cfd19b36315d821b94038c94873aVirustotal results 14.93%Heodo
2020-09-03LpgVW4vyfTbiikFbrqQ.exeexe 5d9ab5976a8b74f6d2a4a104f812198558649d01b8ccd25675aa3b0cff90cf2bn/a Heodo
2020-09-03HgoyoXJPLpgVEyMQq.exeexe 54753cb8f53ff9589e82506b2af029eb336869a5f44c272bb2acad5ad9946333n/a Heodo
2020-09-03VJ3UTO.exeexe 07f579710f8588157c531242e3370310eb47915b91f63a1066a6f439fd9b10c6Virustotal results 19.12%Heodo
2020-09-03LcY.exeexe 05419cbbfc35c2d05d2e6236f65951d91dcc9ee818497e480ffe6bd43c776e13n/a Heodo
2020-09-035T1aWzShBN9DvXukuvnkx.exeexe 5d0d2ed9aa7364deba8e12f6105e73c98b4091efe4225adcb2b29e43a4fa6974n/a Heodo
2020-09-03M1kVc6.exeexe 02c748207da075311958c9eed3a71751d90f2ded0eec4ac3f7f69615b3939a70n/a Heodo
2020-09-03SHTAPk3Lydk1.exeexe 11f97b9044e46805c0fcbbc728c5f07154ead1fd902521811c529e07243ab7b7n/a Heodo
2020-09-03x5vWCopoGp.exeexe ddb93f126808dd86f850fc2083ad71bc501cd08e809fd6dcdd17d25151764058n/a Heodo
2020-09-01nMo4aMbGtrOAd.exeexe b6f2457e50dc2fdd2cf809ebf63577c7277e0e26bf8e87188572c01d96d48f97Virustotal results 10.29%Heodo
2020-09-01sJr7LlilpBls.exeexe fb13df8b0a039ba2084a3a5e4214347716b56fdbd7f3c708717bb439acce3656Virustotal results 20.29%Heodo
2020-09-01KMAnDP29a3KMW7rFFqxuJ.exeexe 3f7ddecca006ea7aec9b6e3c20146dd2ba3d6b0744192a8a560a5c79e52dd82fn/a Heodo