URLhaus Database

You are currently viewing the URLhaus database entry for http://ingridkaslik.com/8 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:47830
URL: http://ingridkaslik.com/8
URL Status:Offline
Host: ingridkaslik.com
Date added:2018-08-27 09:41:11 UTC
Last online:2018-09-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-09-07 11:23:00 UTC to abuse{at}cldr[dot]eu)
Takedown time:4 days, 19 hours, 42 minutes Bad (down since 2018-09-12 07:05:23 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-2866310.exeexe 6c5fa1c0a0c3860b2775ed00c52a2959173d04b597528a1f876bc057d417cb45Virustotal results 13.43% Heodo
2018-08-2811825649.exeexe f8fa091e213aa5cbeac224f8af4337f891ca719c2769ea84f30af31944e5a01dVirustotal results 16.18% Heodo
2018-08-281489374.exeexe 184a9253c0b3c402eeb9839dd516c423be3397b16c124a5962aa883d74f9e7c5Virustotal results 16.18% Heodo
2018-08-288.exeexe ea22cfcd3de0ff240071182f0f89cb1cd8b9fb385c5e1a2abb31f999762ca952n/a Heodo
2018-08-28082495.exeexe 593639d51ed29cab46e6a59b9a03bd98bc97af5f036353e4ad167d0e34480060Virustotal results 13.24% Heodo
2018-08-2876838.exeexe 1e3e70e9b5cc8f1a3b322bce0385f739e306b5e48fa8c240f0df1d718e3b63d8Virustotal results 14.29% 
2018-08-286.exeexe 53f40dd4e6cb92821437712a1d16fadcdba2f23246055a306a3d427f33c5d6deVirustotal results 37.31% Heodo
2018-08-280279.exeexe d19978a6f118c4ae9a2b9d21f6bcc03b35b22d91f306465512f774d082af59d4Virustotal results 27.94% Heodo
2018-08-2857358954.exeexe c3a3da09c6e6b3c9dbf5c714bff9124463b82c4b0c878101d47a08b8efeee907Virustotal results 20.59% 
2018-08-272435.exeexe 7efc8446996e148dcf5b6f490899f588c97cd1140b867098943f6a2b486fcc5aVirustotal results 28.36% Heodo
2018-08-276.exeexe f833b7eb36612e0beeb0ab93d012f544a7f7127a08afc387be115b8b282a2e90Virustotal results 26.47% Heodo
2018-08-27552409.exeexe b79b696f6e3d66512faab754ed00d46608ae1a94c6b827b5292266e73768a263Virustotal results 26.47% Heodo
2018-08-274264944.exeexe 1e61fe9d4ab0d10bf770b06944e80d96c8f533920b27418248f932e05cd84384Virustotal results 26.47% Heodo
2018-08-2797.exeexe 92725be31d0842e5dbcdf86eebd512db9cd59a86fe6ce3369f0ac18732a1f44cVirustotal results 22.39% Heodo