URLhaus Database

You are currently viewing the URLhaus database entry for http://www.hlsquared.ca/FILE/WccVFx1oDs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:552335
URL: http://www.hlsquared.ca/FILE/WccVFx1oDs/
URL Status:Offline
Host: www.hlsquared.ca
Date added:2020-09-18 07:58:13 UTC
Last online:2020-09-18 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 08:00:32 UTC to ipnoc{at}terago[dot]ca,noc{at}datacenterscanada[dot]com,noc{at}terago[dot]ca)
Takedown time:7 hours, 25 minutes Good (down since 2020-09-18 15:26:10 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18ncjAJD6L.exeexe 4a920c21545f411e169dd27c518caf037318617c417196ea78de60221d488fd3n/a Heodo
2020-09-18c4cnyGw.exeexe 4b94b52ee7d791adf9bbfa77724aa3b7965d3455da9d627a37161c951206e726n/a Heodo
2020-09-18TEoWgvlx9WWyg.exeexe 7a4c286ac75e38fd023429262a171ba513daa93729dae12869c424727c82f625Virustotal results 10.45% Heodo
2020-09-186KDK.exeexe 169ca8cc1afa3c3ea8b53f3ea96629721d260206f624afe89e73f87c9fb137eaVirustotal results 13.43%Heodo
2020-09-18PiBslFXDdlJJlpBfei.exeexe 7b016dc17624213911131cd0ccf96d25c97b78460a2f6993d00275e3cb5cc0ban/a Heodo
2020-09-18ceWDDBTO.exeexe 4c966f854d730b03991b0212d7720ad0dae696f81d0145b99396e0a991599eabn/a Heodo
2020-09-18TmXS9jfcCpSO7rf.exeexe 75d46f04354a38fd7e4fef2aee433c144fca060b84bbefb7cce439bb7d296510n/a Heodo
2020-09-18Wwtg.exeexe 264af00a3d468205cb6de9998da60c962dc9f8ac4ae88dbc2005219ff67d668eVirustotal results 23.88% Heodo
2020-09-18EPD2K.exeexe 1ba229358a843cfb4d8b0fe4898b94c8aabb0e6101752f7acc8c668e2493c380n/a Heodo
2020-09-181RYj8wUVVSzscLL.exeexe edcfe79b4a36eddd860306e14dd28d169a851f37c507c5506aafd0fba9d0eb65n/a Heodo
2020-09-18wkV6yBwE7cr3n2M1ri.exeexe a07ca74b5bbf7b933ef480754ab5e80016a171d5f0c7b17d46bb26fcf8e6f791n/a Heodo
2020-09-18g1wsb.exeexe 996c5fa3371a99a347aacf6891c17f8ee45b94276d0af519ab7b076c99f478d6n/a Heodo
2020-09-18tfEm7Ii.exeexe 95cb5ce5677c90632764eefa2a3cd5cc8e1d20947950f41cda23c860f6d282bfn/a Heodo
2020-09-18NI.exeexe f2655043b115a8652107d7444038da913bd5418df17085d0728838f1b01af723n/a Heodo
2020-09-18g5.exeexe 09c274be489c1a413e0ee092111cb66ffa9d9107ccceb00545c87860ce4a7bf9n/a Heodo