URLhaus Database

You are currently viewing the URLhaus database entry for http://buygrowtogether.com/amfxn/G4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:502203
URL: http://buygrowtogether.com/amfxn/G4/
URL Status:Offline
Host: buygrowtogether.com
Date added:2020-09-14 20:05:09 UTC
Last online:2020-09-16 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 20:36:13 UTC to abuse{at}hostlelo[dot]in)
Takedown time:1 day, 9 hours, 45 minutes Poor (down since 2020-09-16 06:22:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16j2nBoUfAMOP.exeexe add61d5f691538d800c6d51f11766825edb171e852e1391973f2c41236d842a9n/a Heodo
2020-09-15Q7s9V3IRDS.exeexe 5d407783380acaa9f2b8357d03555309865a2b75757013696286974249883a51n/a Heodo
2020-09-15G3vMPM3mrR.exeexe 50945120ec1af7cf707e462484f468219c4a5c78bc381810cfb04177e8a667e5n/a Heodo
2020-09-15xfNtxtA7AogsSesxv.exeexe 8f3db0621b334a6cbbd6e2c7edd8b3d4f5958967723d4ca1d88f1d49f36561b2n/a Heodo
2020-09-15ZQquCdfP.exeexe ec862b6019665235dc422b25cbf32a1a341c0986773a25a671ca7e9907238ccan/a Heodo
2020-09-15LmPWnsDbsLVxdeO170U.exeexe 53fa43957fd1646a98e510d8616988677aabcc720589138f4ef186cd821599c8n/a Heodo
2020-09-15s4ozWRLfnKEqSmhNo.exeexe e22ead9608c2252aeb4dd7e4a9fd6404bc79a79dd23841ae196dd3f0b1f66d24n/a Heodo
2020-09-15pUCZIkkefo.exeexe c2032faa688bbaa0ad48a43d55998d737c911882c8e34886c5802649b96bfb38Virustotal results 10.45%Heodo
2020-09-14bu4ENT0YC.exeexe dac30cf89cf49702cfa6f335895786d6e304f964580851b2eae01e3b21781608Virustotal results 7.35%Heodo
2020-09-14Ehx.exeexe b82bb4e2aa1b01131e4feb642cb50728ca2bf53212d418b495b6f40968b5f0fdn/a Heodo
2020-09-14Kx1fQ5.exeexe 82fd4a8d84ad3fcc5aa2fdc97b563ab8439b083e46b62123870510a6e85944den/a Heodo
2020-09-14DpTcQo.exeexe 6b5780d695aa31298a6b27bc1842cbc5a33f30e355777773879480f6c05ee175n/a Heodo