URLhaus Database

You are currently viewing the URLhaus database entry for https://vstbar.com/wp-admin/Hs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:560972
URL: https://vstbar.com/wp-admin/Hs/
URL Status:Offline
Host: vstbar.com
Date added:2020-09-18 21:31:18 UTC
Last online:2020-09-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 21:32:06 UTC to service{at}gyline[dot]top)
Takedown time:6 hours, 41 minutes Good (down since 2020-09-19 04:13:41 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19UwASZCQ2T7.exeexe 3ef4664783b2ddaa9db65802de89060e74b0d0982b8d2c9cac08ae55642fa398Virustotal results 16.18% Heodo
2020-09-19t5qqce5b0PNs5ENMHUL52.exeexe 945d72cb269f2dd2b8474732c9b423eac8710b40f5ab6aed4fc2656f27b8071dn/a Heodo
2020-09-19qsDyK64Puf4q6DCln.exeexe f9feeac7490a2ccaf51fa94ca8621d0ee063c571a72254cb1f2589bfd39ae697n/a Heodo
2020-09-19Nx3dIQFDvDp3fg44.exeexe a31c7ce775ffdd109599f727748ff713327e4ef87d2e10b1bb184884f04558b1n/a Heodo
2020-09-19rxOjRB.exeexe 64a2b4535c30b44fad7f1d58f15b4ff732a8ec36c47c4c7c3aa9c3c526a79755n/a Heodo
2020-09-19gfMYLeoNnuLE.exeexe 1473118cf2e6088fdddffdec01b1de7a2d3540ca1751fc218731008cc8cc3db0Virustotal results 11.76% Heodo
2020-09-19OkM7S7BaqyBBN.exeexe bfec5625010da55f37e29e9d29d962f7c05c0fa911bc6e811d722f4a9508208fn/a Heodo
2020-09-19UdRltNafmLWCw.exeexe 5866dffe20ae9606232b72b218c01900285df20f00fdb72dcac8ca96ae119e1fn/a Heodo
2020-09-19jRiECKsiS63fNW.exeexe eb5f00a8a9429da78d11d29211f3327a7b7dcc8b57652de1e305f482b8d589d4n/a Heodo
2020-09-19bHya.exeexe 6fbb383ad7b50e388c61bd8b64289297e005158da913357474c6de1b1deb3ed5n/a Heodo
2020-09-18h2SKFu.exeexe 2e06104bc8a086f41985250ec2ae04e38492fd922bc663264eec2540a1e5fe16Virustotal results 11.94% Heodo
2020-09-18QQ5sRztai0wAr.exeexe be6f45793d09cad794488aaeb95383ddfdedf90ee38d22a78b331283bfd28f82n/a Heodo
2020-09-18E05itTkUlH1msydKaPvg0.exeexe 75168d77edbd9fe56375046e0873b7996b195584af74b8b608064260bafc8833Virustotal results 10.14% Heodo
2020-09-18DDxqlgx5aUGmEI4z5.exeexe 15fdcd04a4b0dc4772db306c3f36a3a9045ae2fcfe71ad5bbc474efc10cd87a9n/a Heodo
2020-09-180LKInX.exeexe 7252df68953842c8472f23c72f444700bd03559684ea3502341374f467436cb4n/a Heodo
2020-09-187ISy4X.exeexe 64c141a2431c2002ce71e6d785725796c34c2694684fa71bfcf9864f03fad57fVirustotal results 11.76% Heodo
2020-09-18xvZYihrDs1.exeexe bf3d4f2f2a9a8f132b8ad9b62fe040dc76f7d68f306904dd30b5d82012d422b1Virustotal results 11.94% Heodo
2020-09-18ouyGhPOmH5Ma.exeexe 9132b7218df7b8f5a95d9fb5e279c7e5114ed13eb469422b7589e9a925b765fan/a Heodo