URLhaus Database

You are currently viewing the URLhaus database entry for http://iemsys.co.za/fsffa.co.za/2ntFq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:504105
URL: http://iemsys.co.za/fsffa.co.za/2ntFq/
URL Status:Offline
Host: iemsys.co.za
Date added:2020-09-14 22:45:09 UTC
Last online:2020-09-16 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 22:54:33 UTC to abuse{at}is[dot]co[dot]za)
Takedown time:1 day, 20 hours, 23 minutes Poor (down since 2020-09-16 19:18:13 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16D1mn.exeexe b45b6e69169a81915c59d68d5157f52bdda6ce887139eac8b08ba2173851ee62n/a 
2020-09-16eI.exeexe 347ce8cccabe55a5be417aa03204788aa3217677632bb52fd0cfc3c3ae24df5fVirustotal results 25.00%Heodo
2020-09-16jwgPSPBOazkLa.exeexe d765b707ea7529f2df13d4168f27cf408dd95375029b98bfc09c573f0fc842f0n/a Heodo
2020-09-15eK.exeexe 2f8438052db4dde878d4d1ebed18263fb3a65e93628268ea3a3188b7dcd87cc6n/a Heodo
2020-09-15nXPPnVq.exeexe 064f103d1fc889102848b6a8861afdcd73c9804b129ed57ad9e801a609efbdc9n/a Heodo
2020-09-15FK5xVyQUeHCMvVbvu.exeexe 5be7a56599e1da2758bd361a5126bcccd7d66e8c8f2532879475f47e46022bf5Virustotal results 10.45%Heodo
2020-09-15QrHYmoo880zCCYgT.exeexe 8b53378aa6f2c8087c388c6f1ac9e269afeb18a569305879a688dde94011e980Virustotal results 16.67%Heodo
2020-09-15nl7rk5TVOG1cHHI.exeexe 5223edb25f0ff5ae827f333d49ea67dd049c4ce1b366ee639ba396e142bc5ec0n/a Heodo
2020-09-15EJr5nO8AFdPvC1nC8FG.exeexe 472548f41d42cbcf75c18a2c8d5f26f5f1b8ce1298d83e610913fc41b78bbc85n/a Heodo
2020-09-15MeE1y7PDa0i.exeexe 11e8ce4e1abf9d994bf74af6160856b76c2a1b62bd620cde2445db0851efcdc5Virustotal results 13.43%Heodo
2020-09-14wp2RgK4l.exeexe 7f9105d1261267d6186901d2584d32a51c59586b0db4aef4d6cb6ccd97bb8cb1Virustotal results 14.71%Heodo