URLhaus Database

You are currently viewing the URLhaus database entry for http://fourtion.com/qyBf2DfGd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57965
URL: http://fourtion.com/qyBf2DfGd
URL Status:Offline
Host: fourtion.com
Date added:2018-09-19 10:53:56 UTC
Last online:2018-09-20 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-19 10:54:05 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 6 hours, 41 minutes Poor (down since 2018-09-20 17:35:06 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-204l5jMtDz0.exeexe c2da9ca28d2ebedb8a6d9aa8f2135d8ea0e7766a6f50be1553a67233399ba983Virustotal results 26.09% Heodo
2018-09-20csGS7Yl8P8Jd.exeexe 3e96bbb09d9a4579062af554a2ddf5d130d2b4b07c830bcbe0b322185534eb05Virustotal results 23.53% Heodo
2018-09-20ivGaPoEQzb96.exeexe dff2ec689ac03743b1ae1c9332b0f3520655d4804ba742dea6fbeb6c79a289cbVirustotal results 22.39% Heodo
2018-09-20Xzwd4OsQm.exeexe c6eaed502b28df062bf24a3a18ec6f345985d3f8dbfe5afb502d3c272212fbf0Virustotal results 19.70% 
2018-09-19rL2XEez7Sti.exeexe ceedc9eceff03241ae88bc8a0d6f7f9fb050cd190617a6f16b300c66bd627da3Virustotal results 23.53% 
2018-09-19ArTdLqxn.exeexe 66a27b7a9c01a84438f93b07759fa6800b389069cd0c29a1ba7f9556a498efbcVirustotal results 26.47% Heodo
2018-09-192pEdDC7XAw.exeexe f5673fe04d3cba4e541e028b5ee1201e1abfac6e1327d343d0c5e2f1fd5166c3Virustotal results 20.90% Heodo
2018-09-1906DBjxvO5v.exeexe c5b7e9290b8b4c235f5d946baa2074429e89919abf83f450257c54cf2bdadcd1Virustotal results 17.91% Heodo
2018-09-19Phm49sXp.exeexe a99b1b488f9bfc18020c0284386a0d5b7e8c622a3481268e6ce94c51a001ca0eVirustotal results 19.12% Heodo