URLhaus Database

You are currently viewing the URLhaus database entry for http://www.mcsgroup.co/multifunctional_resource/XZpnWJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:552339
URL: http://www.mcsgroup.co/multifunctional_resource/XZpnWJ/
URL Status:Offline
Host: www.mcsgroup.co
Date added:2020-09-18 07:58:19 UTC
Last online:2020-09-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 08:00:04 UTC to Dinesh[dot]mh{at}ziniostech[dot]com)
Takedown time:1 hour, 45 minutes Good (down since 2020-09-18 09:45:35 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18bhkjK46VehKF.exeexe 0286799bcd13cc95cbf9f33245d2fcf23ccd09343344bf391006ff468853e6b7n/a Heodo
2020-09-18zvLqwx7LRLy4LD2O20.exeexe 3243397a55ed56e859c88cee2c3c2c30f3f987456600f11c64faac5454151832n/a Heodo
2020-09-18yqqCy68hVW89OUo24Ps.exeexe 015bf07c63bd81f4ff506fd2facc2ec546f2ef6bf1856176d469e1fe92167824n/a Heodo
2020-09-18zvdHchsKynnw9TPXm2s.exeexe 1727324056de44a7e63b54517a328d259812e26f13d05d50092805bfab365981n/a Heodo
2020-09-18elMr.exeexe 5d9ffe09ddbd6e055fa135ba2302f16fb19af57e3c1858d916c13a9a812f1a90n/a Heodo
2020-09-18eNNyvWcFH1S.exeexe a5e36c2428c4f47163fa470cfd8bca0f64f16e53a2f41696632f5e0c0e804c71n/a Heodo