URLhaus Database

You are currently viewing the URLhaus database entry for http://votesteve.us/closed_zone/Bk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:552952
URL: http://votesteve.us/closed_zone/Bk/
URL Status:Offline
Host: votesteve.us
Date added:2020-09-18 09:17:19 UTC
Last online:2020-09-23 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 09:18:08 UTC to abuse{at}wowrack[dot]com)
Takedown time:4 days, 18 hours, 21 minutes Bad (down since 2020-09-23 03:40:06 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19Ir7mF0jGvgTiF.exeexe 0b75368fb66f5477680e42bf7b66da961ae99dd6653254ffa8165c314e75cff5n/a Heodo
2020-09-18k91.exeexe 11e0f5eed7d3612a6b02fd4df562927ee30ae08d618c228667797507463e7d2aVirustotal results 10.14% Heodo
2020-09-18zU9.exeexe 8f5417962f4173b18be5dadb19ad2a567f426463e1df4d2b43e9ad5a1c950a8eVirustotal results 11.76% Heodo
2020-09-185BiqvBgNV6OGbj.exeexe 60d380179854197895036382e545df9c3a428a01729d707b9395a475d83a329dn/a Heodo
2020-09-18jujz5o.exeexe e45e556a01c0f43d992f96245a746ed01f7522f2b03416e0a311584145fd08a8n/a Heodo
2020-09-18Az1CRpI4.exeexe 73f4d68efe829d98e638e79f396c82add1ef6c64b56e08594fe325fd365cd941n/a Heodo
2020-09-18chhspSyTZqYzgC.exeexe 7b6a322611693356d3c01b20afb229c072a163b9d8c1abf4cb1c7f2dae536ce0Virustotal results 11.76% Heodo
2020-09-18ayV8lKJCsHRdc1mvTcS.exeexe b59c0ce943fc58d572ec8d51a18ce8886c2e99a615375a296036ae3eb461ea13Virustotal results 9.09% Heodo
2020-09-18pvWTb3j2mQO3wwlj.exeexe 27302084548dd896a8a59edbdf27cac1f03142edc9456b5efb49c4ec6601a106Virustotal results 10.29% Heodo
2020-09-18g.exeexe 7ba1660d15d6a9b6bc0cb66ca548c225175ef3af563b650cef18ff8c6d12c180n/a Heodo
2020-09-18PwVAvvSJW.exeexe 40d6ff3ab04aa7c8cd8a47f1bb16bac7c9f8891dda306af6a6297666359e7a4bn/a Heodo
2020-09-18JjfCRu7b8LIIBIf.exeexe 782534fd2a9c97674fceb51d69d570ba4f22a73e1f68514d76fd13f4eadc63fbn/a Heodo
2020-09-18cS08FQg6tD2.exeexe 5845a9e1607ff7507dd8b7e0bf033367f1d14eff5e0bc614ea306591125b959fn/a Heodo
2020-09-18ZHssg95HxtBd.exeexe f2e1104a85e8f618f7136e6b6cb65448556c1abcf471ef214cdc5a6377e91ad0n/a Heodo
2020-09-18JLatf15.exeexe 987164aa4882eebf19ad463ea32d2b245fa3b9c547eadd137fcd727ad293d496n/a Heodo
2020-09-18uy7bS1avp.exeexe fa94ecc9b9fb4fa9e039d70ff53813f6b385fc4e1486593192bec3c42fcea1baVirustotal results 20.59% Heodo
2020-09-18bdrpW23lvtn.exeexe b6547366bf63c1dc58cb91e68c9f735522a2c19b0b15ef1462f0d371024722a1n/a Heodo