URLhaus Database

You are currently viewing the URLhaus database entry for http://avto-baki.ru/6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:53495
URL: http://avto-baki.ru/6
URL Status:Offline
Host: avto-baki.ru
Date added:2018-09-07 12:33:13 UTC
Last online:2018-09-09 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 12:38:48 UTC to abuse{at}best-hoster[dot]ru)
Takedown time:1 day, 22 hours, 58 minutes Poor (down since 2018-09-09 11:37:28 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-10n/aunknown 548da4093681d819d1ce0600b7c6a3f0884f8d6151c700374ee162b49d9a420cVirustotal results 0.00% 
2018-09-0864396403.exeexe b37218e666f643ded336e1f7f56cb8b7a87b6edf1c015359f074b74b0c7923dbVirustotal results 19.12% Heodo
2018-09-0865.exeexe adc0ab84595cf362dd20fda29d0a427bf3b7579002155be8e304753525a5c399Virustotal results 17.91% Heodo
2018-09-088859.exeexe d0048ecf217804fa1ae0df3a3d5305e4c970694b84aec96564234f71dbf812b5Virustotal results 16.42% Heodo
2018-09-0810065197.exeexe 9c674bf8ce4b162d412e673c58e3af2383a120934eb910b624a74821f53dced1Virustotal results 17.65% Heodo
2018-09-08839.exeexe 0360e85f89d56887b255db785b2b28f2ee519cc1cacaaaf790cbf3ec57626fd7Virustotal results 22.39% Heodo
2018-09-08391110.exeexe 9eabdba5c7f636947527866a3e24f0a8450583479792203660d9434a165a5334Virustotal results 25.00% 
2018-09-08203.exeexe 767e2f7a7e9053e892356241ee5ddaebb4a6f2978b65100d171ca56896839ad7Virustotal results 23.53% Heodo
2018-09-08358877.exeexe fa5825b4efd2cbbff9a6ec4d8ea8d574ef82b148c7f7ec6bc68a613e8afd9d2eVirustotal results 16.18% Heodo
2018-09-076433.exeexe f8f5a20829b0026b886688e782298ba8e1232f20638389a4a9ec3f1cd6dd32efVirustotal results 22.39% Heodo
2018-09-07126447.exeexe ff65f7232b46384c18d951c123e09599335d5fdc0c89453cd10ccf95b1746ea1Virustotal results 29.85% 
2018-09-07651.exeexe 75b528e510e325306ddd5a9deadc529fcf6a5bf37a6ea835e35ea6cff94fa117Virustotal results 25.37% Heodo
2018-09-07275355.exeexe bfcd0bbf353b9729bf0ea573b8b53c7e3b09917f9e87910bb89f65d847117560Virustotal results 22.06% 
2018-09-078267.exeexe 879063c319a26ea798475c29f071f428694dbe626156856c58d6743993fe022dVirustotal results 28.79% Heodo