URLhaus Database

You are currently viewing the URLhaus database entry for http://taltus.co.uk/EP4L639 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:55748
URL: http://taltus.co.uk/EP4L639
URL Status:Offline
Host: taltus.co.uk
Date added:2018-09-13 05:30:06 UTC
Last online:2018-12-24 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-13 05:32:06 UTC to abuse{at}bigwetfish[dot]co[dot]uk)
Takedown time:3 months, 12 days, 1 hours, 19 minutes Bad (down since 2018-12-24 06:51:09 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-24n/aunknown 0479f4452a4c0acee2ba72ef9ba54107e094200dc2e0ac1b27b30344a2de4c8eVirustotal results 0.00% 
2018-09-13zhbmrnUgE.exeexe a74967811f710d6c2d2d6d2e061e14d9bbf6e61646ecd580715ad40088e3dea7Virustotal results 14.71% Heodo
2018-09-13d4GXYnYH.exeexe 5ed869578abcc9f9e4983adc3482394f231b2144a36a34be75694f4280fa4581Virustotal results 25.76% Heodo
2018-09-130WXOWBVBRFI.exeexe 82e4585f249339dd5a4a38b526e705d8b5a23a51bc2ea4fd2f9bcd979bef8f7eVirustotal results 13.43% Heodo
2018-09-13hCFIiFIQV.exeexe 2a24d5d2fb44adb3eeb4d2d5d031ebef0c43f316922e186eaf12a852ea8dcd60Virustotal results 13.43% Heodo
2018-09-13MeQeYx37CjU.exeexe 78cab845b041d60868a8da045da24e4325001869e10b0cd1390c541a3a05e50aVirustotal results 22.06% Heodo