URLhaus Database

You are currently viewing the URLhaus database entry for http://ebu.no/billett/VMs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452449
URL: http://ebu.no/billett/VMs/
URL Status:Offline
Host: ebu.no
Date added:2020-09-03 13:33:07 UTC
Last online:2020-09-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 13:34:02 UTC to abuse{at}enternett[dot]no)
Takedown time:18 hours, 37 minutes Good (down since 2020-09-04 08:11:02 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-0400095OBTq3.exeexe 8f43b4e551c7363ecb4211d90290cdd1041472231fe58b3dc5768d6c40fe0de1n/a Heodo
2020-09-04rjqc7n06250137.exeexe 623f4a52c51bb4e0e108a7584a0fa7c6f919a17feab9961a3edc6818e782365cn/a Heodo
2020-09-04VPbjQwSQHrFAEb.exeexe ce929dbfe74b7241783aab60ad10dc3abcc7c3fecb147b1405aee6d124cc0135n/a Heodo
2020-09-0400174Vq.exeexe e1a2893130c6c762c9213a4c8fd1d23a5724fd4f2c6552fa17b30cd3c41ee5f9n/a Heodo
2020-09-048d0598298135.exeexe 80a328655b5d9c9e43b97f7e6c29476d179309c382b30607e6fa733c7fea2371Virustotal results 18.84% Heodo
2020-09-04Wg0.exeexe 2a3a91caaa3fbecc971c8c4649f20f1ca42b2cf73172649e70dbf257710a00d0n/a Heodo
2020-09-04866.exeexe a90558821f86e1555ffd5a1fac697b7a1347f6f77dd8a80185ca8c11c219b32an/a Heodo
2020-09-04008ISD.exeexe 3c42edd95e3f8580f178cff5aee1d1e6e6b52c4ba6dc257fe6241cd7b220677en/a Heodo
2020-09-04nXYYy.exeexe a80efedef9711f14795fc4a9300b2126a1db3681a6d69f47d812c1071d1dba59n/a Heodo
2020-09-044QPqkX34032523112464.exeexe 826cbaf7cc3957bb53d9c3f54c5ee515908de08ad75dea4fb9941d13603cc11bn/a Heodo
2020-09-040038ZWLL.exeexe 7048bff76d05bd07ad0da16ebaebc33d96342db0b3c4a01a26783f5f45bd1ad0Virustotal results 15.94% Heodo
2020-09-04000045786531203.exeexe e0e9b6d7725e96d1438577cb55a2a5e3314ac41f7563164a20492d9d248d3e67n/a Heodo
2020-09-0494727Cf.exeexe b8ec2af653797135ad5b4a56198995f9129ae2d394f33007662ece121beca036n/a Heodo
2020-09-040006552245335868.exeexe 8c9355074057b6c6329e7de8585fafb9ea09d61febc61d9a5aa154fb2cdb1d55Virustotal results 10.14% Heodo
2020-09-04aaHvdRyfMOwO00000227879240.exeexe c0b35f0a305b46460f2a7210974f9db742c4ff6613f4078723050d8f389a9f3bVirustotal results 10.29% Heodo
2020-09-040CaRbUP6Y8501155.exeexe 5b05ac1953c5196a05162fddba9ae1bf90ec3084ddc6926eabd65710fa5b6afaVirustotal results 8.70% Heodo
2020-09-04ikKTjUkGveO.exeexe 004f6532374c1f73713084d83f78ed93f5bf3eeace18a339d7d9f689161ca574n/a Heodo
2020-09-04fj2e.exeexe ca0405b6981e8fad8bfd29665e5ba4f92f5f7b883c69866e07601d141a713633n/a Heodo
2020-09-04000H1bDdTniGM.exeexe bf47135d0fbf1f1a84922a369b6ac5c24eae2ef82dc66ee15da16beb7b9619b5n/a Heodo
2020-09-0400010qFHxjaXMexiS.exeexe 7b58a295cc822885cec4de3bd0fe8f93aedc1db12269a40aec4b4a21974ec346n/a Heodo
2020-09-04KfANQFnKCDSUu0000497695.exeexe 823f7ad24706251f4e084fd6ac4ead7143af56b1757c6de36637e15a0f938ac2n/a Heodo
2020-09-04AjREa1n7NHDT00006780739.exeexe dda2e3f73e5a3f45f36454b71ae5410b0d098f277f91acada36af1d05e0dc3acn/a Heodo
2020-09-0499X0ioo00000942.exeexe 253cc9df6047730aac0d2c315775c0ddeb22ccabd2e4ebf7565737ad0b04089bVirustotal results 4.35% Heodo
2020-09-04QQ0000449004794106.exeexe 840656b334ad962ae8aa0aa82ab40ab7292a00ada74e0067cbc6fa9c47f14cefn/a Heodo
2020-09-04006362923UkTO.exeexe 08df7c4b0925884256aef7e7c4be9809214251321dda0fd4e879975ba2083a46Virustotal results 4.41% Heodo
2020-09-040074792.exeexe 5573f06bfd2908292c968deef22e043b06fc2194f2601de59fb9e8bc2d5d2ef2Virustotal results 5.80% Heodo
2020-09-04067NL6e6bRRX3jb.exeexe 053568a0fafd3509fa8b1da72b92e9a4807ce1b5a5e4365e4a5cc120123d0bfbn/a Heodo
2020-09-04Lbx6xw1E77.exeexe 7845a120eb3e2870e48003f134d80ad66225dea07b79429024a18ad249c4d247n/a Heodo
2020-09-04dW7n.exeexe cfd89d038b0a6aa1001373814e65c14250dba614df0854c801e3400f17a57e66n/a Heodo
2020-09-04mqKy35094873335185.exeexe 38f76836fd6c4d1171bea496697a2057b9097ca026838394f0dbc87d01ded582Virustotal results 4.41% Heodo
2020-09-03000050965960423995.exeexe a951fcf4749636a911d0a1cb072fd9cf2ad4d5c886c029d27b9459638a7ff9b4n/a Heodo
2020-09-03eR.exeexe 8182bb1df749da43808ed1706922d58f017cab8e47504fe84fe24e43a11e001an/a Heodo
2020-09-0300063521086526656.exeexe 5a32fcf7675bb2d9196543848b983705b77a211cdb4d08b055fac85fdd70ff1aVirustotal results 5.80% Heodo
2020-09-03g7Dt0.exeexe 6eaa7264e5e06e46bc92dc85743c1742587e4726786e9a3cc4d3676539f46554Virustotal results 5.80% Heodo
2020-09-0306eaH.exeexe 5035b128f47ba0b7241ccd29feae128609490305777f32121891eb6ca0b66e71n/a Heodo
2020-09-03BLXrqWWN1c.exeexe daea21de007a5840a6546ce76055b725a1e95ac2bea7001b1bc6751635f8022en/a Heodo
2020-09-031cL6.exeexe efe613c5e31878752a788f7ad60831885a8427dae468a28bb2cfbf51952c9f8cn/a Heodo
2020-09-03jmIA.exeexe f9c34d416d02784fb98800a6cd05d71f7f5a48adc8b62342896ab00700a30e7bn/a Heodo
2020-09-03Drto02ppjz6204870344688.exeexe fdf42a7b32461feff0647d8be074f0385490e9c81b02d4e954e2f8ffb2960505n/a Heodo
2020-09-039894879069171.exeexe 2e81e0395b28cdabdcc5f197299b1b7131d251b68903cbaaca0da0ef3a7299f9n/a Heodo
2020-09-03d54I46gMIXvNL.exeexe 6827884b1247161d8c5dbabe7a6dd1c06e90c5a76c6e3389e1b45e4d575f620cn/a Heodo
2020-09-03009199321315075KuXkpQje.exeexe ee3afa261555fe22ab46e7b0dfcedb48ce457440abb357b77444349b18c8418an/a Heodo
2020-09-03KUovZs5Xc3Nrcr.exeexe 8a7aaef523348af0641d6a829aeb53b354ac86b33f4f642c8d71983faaffcd55Virustotal results 11.59% Heodo
2020-09-030095456756929.exeexe 5da9095a90a83f3608c1db33f394647490ef0905da775176a29f7fe441998188n/a Heodo
2020-09-03mDe.exeexe 51619291f5771f04f4c2cfb357d5b83b4e0c4e807f1aa50c3ef7f956898dceeen/a Heodo
2020-09-03qUhJXGehacbRN00185991216.exeexe 46599f979e032799cf0349438254b8817a0147a32fb7fcfe3b77ba3b3b6828b9n/a Heodo
2020-09-03aTIw.exeexe 0c97c11d243eb9ddc58e118e03da2174ddf580d3c805662ebb3defc1191d090en/a Heodo
2020-09-03hgn5Wayy06.exeexe 5dce985765fe8e2815508c94ae5a2e0516ec554c326ba9058b961a0a8471b5bdVirustotal results 8.70%Heodo
2020-09-03000433925042YYjd.exeexe 71c05193258e1f9d958d67432d0c92c64e1abff893edce944ad90f939acbcc62n/a Heodo
2020-09-03lB5515484.exeexe a9355393257f9608dbf875ef316828679456098cffbf3cbd780442758604ad32n/a Heodo
2020-09-03l3QOLfQsTHxSgh.exeexe 4b718755ea1986f3b8f1e747911ad5e200a6de8dde59d24b8e503777e191b1a8n/a Heodo
2020-09-0300000581189905.exeexe 53984fa816313fa6a5c7afb753d43f091372f7159b989b51efb6163efc2f42dfn/a Heodo
2020-09-03kn93929244472729.exeexe 4298fd041efe80fca8daa438a2e228cbfc8fd6cad42d8207bd491a599baf5341n/a Heodo
2020-09-030025077860792VuvQDHQlBQ.exeexe d87366a3c21d3cc452c0315a07c2fb87c985dccdbae2316ba42ff0bbced4b769Virustotal results 38.24%Heodo
2020-09-0353709001nntux5.exeexe 633b847027cfcdd22b538988dcb89605de5b5c57a9b6a5930431b1fb8ea50e5cn/a Heodo
2020-09-03BbA8n7i0964702943948.exeexe a416ce90440ec1e804b9673aa2831fdacf41d366998d963f2bf299897b4b7f99n/a Heodo
2020-09-032O1AVTPdRZ06428772665.exeexe bb4cb90ee592613e8cddd8ce10699145e5ead644717e62468720fab2d6d71fd3n/a Heodo
2020-09-0300448596758Xhjy.exeexe d897225f5fd565a886d2fcb9923c65c7456e322978ed3135ee742d4c68e6acc9Virustotal results 23.53% Heodo
2020-09-0300003VACggQ.exeexe e9ec64d1c65d9883dd607d95d4da13c17ff7df3367a21e67e229649e1af5bda2n/a Heodo
2020-09-03c72.exeexe c9e587bb1b7a18ebd80a26823d345e96590bb0d48b3fe4033842b68194bc80b4n/a Heodo
2020-09-0300271807rcr6398JZD.exeexe bf14a31564906cb51f9bf352e9ab423f6630d82f256ffa80c913f6e6ae69a69en/a Heodo
2020-09-030001933391.exeexe cca617a22b64b7ad442eab53a4ef0580ba63bc523866c881199937e69e0c202dn/a Heodo
2020-09-0305zQfiDPEAX.exeexe d332183cd49e89c3944aba4f0561f34b11a1fc762ba473c3841fa1ac86eb2556n/a Heodo
2020-09-0306QMUqyTdP008850439497690.exeexe e1c932c363011efeac2991303a4c97cc3558e026d8f464b7c91878a5453e578en/a Heodo