URLhaus Database

You are currently viewing the URLhaus database entry for https://egfco.cn/agxqa/ANy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453583
URL: https://egfco.cn/agxqa/ANy/
URL Status:Offline
Host: egfco.cn
Date added:2020-09-04 22:49:06 UTC
Last online:2020-09-06 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 22:50:02 UTC to abuse{at}hostease[dot]com)
Takedown time:1 day, 8 hours, 36 minutes Poor (down since 2020-09-06 07:26:51 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-06dEpVYmz.exeexe 3b490131cf1268e660007fa372d3ebb0a69c6c4f6050686b849b7ced65072313n/a Heodo
2020-09-0568xfvfwzp8.exeexe aeac42c761decd3fbd23d7306a2c7d1432fbc5803f6af609f3ea956118fec983n/a Heodo
2020-09-052ztye.exeexe 4557b4d500a4f7290b2fb4f751e9042a81071a28a5d8d363db4af914e81fd9e1n/a Heodo
2020-09-05O3.exeexe adbc444325c367a3497820b97dec426fee0a9b8fb55162fd3d67c6c9059f6132n/a Heodo
2020-09-05IvlQHA5SiNWe.exeexe e3638215edfcea00b3c018e35ec0ca0516a1a4d4c2fa3424edda851d1d73877dn/a Heodo
2020-09-05obSuI.exeexe 26180b718b5685f42f3821ae409cd7fd95fff8b54de0eb5f5d872f85db2bf6bfn/a Heodo
2020-09-05YPxnY.exeexe dd53955f68f78602bba4b5803f48348ef155a3a9adcb22de99be04f352e6d08bn/a Heodo
2020-09-05lpHW1m.exeexe 973488a67b9a543cde1ee83ec034a8a50d348e80fef71645f191c9ab8684cce9n/a Heodo
2020-09-05Rk.exeexe 388a7915780ee93a766cad142b6d9cf5fc29236ce70e694a8cc975379f18e803Virustotal results 8.70% Heodo
2020-09-05bJjLB25X.exeexe 8afbf819d0627b22ddd40f110acc5cae26ac60bf9170a121942be6828d9c9fe8n/a Heodo
2020-09-05WqKzt8LNjL70.exeexe 7306a277281207bc7753d74651bd3b1b5d10b0d40e7ab3397640927d7494d7bcn/a Heodo
2020-09-05fizfHPjpW871bLay6B.exeexe 074dcddf4fa4cb373c5e558eb2626d4555e064aa04411514a399946f3cd13954n/a Heodo
2020-09-05f8BH5s2Bt0XZeAtuRm.exeexe 53c56250398068c70fd91dc603fabf259b40154709747d5043ab293ca7262e51Virustotal results 7.35% Heodo
2020-09-057.exeexe 462a760bf47df20b2cb745b9c987c4ca47c93b11c439e63c6ab3eed7894cd23en/a Heodo
2020-09-04MmhJTQeYiDh.exeexe 48e2384fb49dab7b1052a6abbaeea03ca01785db8f2e034ee6a73acb553ed2ddn/a Heodo
2020-09-04IVJt0F04.exeexe f27096d1f90d851b58ffcd0af8bf420d482570ae11ba8aecc486235175f97dc4n/a Heodo
2020-09-04rRurDXtviTW2R2NCrnR.exeexe 6fe7f56e4292b048fe4e0f9bf770ed0b38ae5430c2978bee02aa19e6d8de6be6n/a Heodo
2020-09-04SE8BlryNbxJc4HaqG.exeexe b6d69240f5fe1f2f1aefde944eb2ed23c1190ec30b661dc1e80e9bacf40b5b36n/a Heodo
2020-09-04XuB.exeexe 4cb47731a5647ee8f8fdaf4b986b708cd589195636880c1ecaf46d4ecdaca425n/a Heodo