URLhaus Database

You are currently viewing the URLhaus database entry for http://downinthecountry.com/KV which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51965
URL: http://downinthecountry.com/KV
URL Status:Offline
Host: downinthecountry.com
Date added:2018-09-05 06:26:32 UTC
Last online:2018-09-17 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:31:22 UTC to abuse{at}turnkeyinternet[dot]net)
Takedown time:10 days, 8 hours, 54 minutes Bad (down since 2018-09-17 20:26:08 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-0661.exeexe f238c41168e5413f60e929bcf7efb8bccbf4fbb640758c938c43ae43d94369d6n/a Heodo
2018-09-064876380.exeexe 99f1834ac8f472867f3f6d2cd757a3c117844f42ea622e9734cb6332db97893bVirustotal results 22.06% Heodo
2018-09-06299973.exeexe 3455a9434fb5827ac86641dc05c3d45f027d5b745e45246c3922f37adbab00acVirustotal results 20.59% Heodo
2018-09-0693933.exeexe 18c148661da9f1efdeeba54566d83e98fa5a9c74189dd2b6886352dea656f4caVirustotal results 21.54% Heodo
2018-09-06818718.exeexe c32d03f488107b0d337587fd57e84b55630fd52da351d8ebdc5f43518b6cb2d6n/a Heodo
2018-09-06402.exeexe e8ab76330d004017f6e96aef9da1995baa865e7f6a9315676a40d89b0380fe78Virustotal results 16.18% 
2018-09-0688550244.exeexe 738101c93e726ba3189364183cd40277a5365fda975435bbad830b108454b6e6Virustotal results 15.38% Heodo
2018-09-05570518.exeexe a30430a4ab3cae0c89a82064a122de569c6bf70eabeeb4d52fdd6b476a3a04b1Virustotal results 24.62% 
2018-09-051399155.exeexe 1ab8d2637d578684cc71f2733408c1cd23a785492fcdbc3642f7a2cc1b177843Virustotal results 17.91% Heodo
2018-09-053128179.exeexe d9052b01b7fa4d9209af5bb98a569d9e1855e11cf0f94bb02dd93410a7163a5fVirustotal results 20.59% 
2018-09-0520091.exeexe e8abead21f2da76ededa6e23ec310a7958ae9a1abde4b69968b29239010f37a2Virustotal results 24.24% 
2018-09-05509610.exeexe 70ec894e91e68f741b29152e29bed10bc5374c09273e3317d246b3931d1559f0Virustotal results 29.23% Heodo
2018-09-05271491.exeexe 673a8f833ebe06c5b6f495c8423a6fd4ae777ba878654313bea31e014558776eVirustotal results 23.53% Heodo