URLhaus Database

You are currently viewing the URLhaus database entry for https://adamant.kz/CVjsyDag which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57183
URL: https://adamant.kz/CVjsyDag
URL Status:Offline
Host: adamant.kz
Date added:2018-09-17 17:05:24 UTC
Last online:2018-09-18 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-17 17:06:06 UTC to abuse{at}ps[dot]kz)
Takedown time:18 hours, 20 minutes Good (down since 2018-09-18 11:26:34 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-18ejoIY7vHtr.exeexe 647b161df143213536ccc70a705289f7118780026b79eab6972c76a3e3769e5cVirustotal results 17.91% Heodo
2018-09-18B1qcy2PK.exeexe 9287f1567b0c55657b6e77b67176f7b416c22f2e9e7d2298b90817953fb84a56Virustotal results 22.06% Heodo
2018-09-17cu0aAoWf2.exeexe 59b8bc6ac157a553440978406c8aa8eb8a25c166af11754e1fc1aac3e65c8a59Virustotal results 17.65% 
2018-09-17U5O0s93gf.exeexe d063bb86015e4800b2a136cb32733bdf3b3da9e5f92dbb509d6687b4e6599f14Virustotal results 20.90% Heodo
2018-09-17wZl9WXXDPkbK.exeexe 82c2b966e981e676afeb92ed93d0be88a203417929b9abaaa4a4aba6a7f83821Virustotal results 24.24% Heodo