URLhaus Database

You are currently viewing the URLhaus database entry for https://xn--mgbao2hg.net/cgi-bin/1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:502207
URL: https://xn--mgbao2hg.net/cgi-bin/1/
URL Status:Offline
Host: مانجا.net
Date added:2020-09-14 20:05:16 UTC
Last online:2020-09-14 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 20:06:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 6 minutes Good (down since 2020-09-14 22:12:54 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14tbal08iBaNrtyC6.exeexe 346364be57f4b65cc31ffcd1c122799651ad54b67bb3e4edf181c9829d67ca5an/a Heodo
2020-09-14TbcrNBWcdOaCPlzjtvlY.exeexe 1967853c46ff049a1f8c3568b54e19b160056458d2627f13f0fc6c3b27553039n/a Heodo
2020-09-14hf6oEf8BNM.exeexe 9abb02ca7bd8de600ed4eda4d29239436c9b9620c49c1cf34df1823a57292daeVirustotal results 7.46% Heodo
2020-09-14pJp3xA1vtL.exeexe 2bb8fd4ea0894fc240f5d1845bc01edc7510aecc508264872c4a08c9a276060fn/a Heodo
2020-09-14Ap8rJwVKP6qbolPlNEpLy.exeexe 03bc2fe0099515cf4725a6ca57d5bcc03d2b8002b6967ffd1bded7020375bd20n/a Heodo
2020-09-14gitYc1G5wd.exeexe 95059f99f0187315be3c147c3494111a62ee469fe97b3cd05a65e795ff9ee114n/a Heodo