URLhaus Database

You are currently viewing the URLhaus database entry for http://milehighffa.com/Wn0Kwn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:54794
URL: http://milehighffa.com/Wn0Kwn/
URL Status:Offline
Host: milehighffa.com
Date added:2018-09-11 10:49:12 UTC
Last online:2018-09-14 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2018-09-11 10:50:26 UTC to abuse{at}godaddy[dot]com)
Takedown time:3 days, 11 hours, 58 minutes Bad (down since 2018-09-14 22:48:44 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-1263290317.exeexe ec03e37b54257cbc3a1cef90efba9fa6cdf988c7f4197aec131e98b8698d816fVirustotal results 11.94% Heodo
2018-09-1277831801.exeexe 74e426f6b6a5657d937e78bac99afeec3bc3e8870248dbd3de33340cb39e59a4n/a Heodo
2018-09-125.exeexe 4718cf64b06755f3e2d6551005fe88c0e50e3d2644e873562804a4e7da9b6ee8n/a Heodo
2018-09-123460.exeexe 6f1a1528f048916d8de6c0b3c7475aaab36f42bca415a1f04d48e229542c78cdVirustotal results 7.35% 
2018-09-1232344416.exeexe 87458125a55b3783ef76701a2dcbea766dc8bbd2768cf89c5f170ca4149f8bfcn/a Heodo
2018-09-1285701338.exeexe b8d53325f6e9192830b26695b637b2942dbd2063b801e6882aabeafb94807874Virustotal results 28.36% Heodo
2018-09-125971.exeexe 56da7f3aa2f8f0cc77653779eedcc10250409e4d16833c553c81470c6ade4126Virustotal results 28.36% Heodo
2018-09-1186605.exeexe f50326faf049933de1d6145d0ba52e917c604c4735f0ee786d05e42efc52e972Virustotal results 24.19% 
2018-09-112651.exeexe 4b648b59f8125d004de16a949c3b6cdd71b5fdac057a9029ac8872087e4a79f3Virustotal results 17.65% Heodo
2018-09-110924.exeexe 65b40c9e492e7fce7451f43980b158761e6b41d1f48ef50236c5fe8a843c03eeVirustotal results 22.39% 
2018-09-117789.exeexe 724db0a9efb73071e155d351bd1b7bcd279a67ad27911d3ca7782af183380209Virustotal results 13.24% 
2018-09-11050.exeexe 13e65411c8c101cd20e78e71ee08efd1d51373e491cde15f639a147a8ec1330bVirustotal results 24.62%