URLhaus Database

You are currently viewing the URLhaus database entry for http://themsc.net/cctqv/M/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:582271
URL: http://themsc.net/cctqv/M/
URL Status:Offline
Host: themsc.net
Date added:2020-09-21 04:37:05 UTC
Last online:2020-09-21 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 04:38:07 UTC to abuse{at}alchemy[dot]net,dnsadmin{at}alchemy[dot]net,support{at}vitalix[dot]net)
Takedown time:3 hours, 45 minutes Good (down since 2020-09-21 08:23:59 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-21bONNJLD.exeexe f172035fa5b7549e8ff4a18f595d578992b48b08aeb160b9cd8c3c76bfe9c8a2n/a Heodo
2020-09-21dNvJJirTcF.exeexe 6161745eeb83353ec84b0778f42af77d1c433613a57a7f6c27449d203f4d812bn/a Heodo
2020-09-21Wx5cAb7XhhUujh8.exeexe 0849bc5f08f2f98a642e5d503f241a32a320cf4a4c24ee12c993b1537fdd0340Virustotal results 32.84% 
2020-09-21TWdJzQRE9Ghvsnix0pMfr.exeexe 8890690828a0e3eb7a283d110b8b51543bc709857f758142018a9ddd45e66e25n/a Heodo
2020-09-21qQY.exeexe 546610b2f75ae0b248dd9eb893eb12921681392a15673ef8ada7857756e0abb8n/a Heodo
2020-09-21PeJv9xnJQ0JlN4DCmKK22.exeexe 6b7eadf91e7ccf7296dd6232f7ff00663d9895d6e836a1305c15d178f5b6b56an/a Heodo
2020-09-217BcL7brnxqoJu4A.exeexe ec3734b09490e81f97b62fd45990823835bcd4f4ea5899fd74151948f7e3c54dVirustotal results 30.88% Heodo
2020-09-21c1G5.exeexe 598c9f16880f5ae24e5fdbe2fac014dd0c5ba462840863c212ef67a3203d7835n/a Heodo
2020-09-21lcr4hx7dSwfEmm9.exeexe 9382d965f728c91fef7603fee0090437f3602701b243bd8967028055e75e16a0Virustotal results 30.88%Heodo
2020-09-2152rxGPvVU3IshkFFWtEK1.exeexe f2e9a791d472983f48ef1e182997cd39ee8118ab83c243ceba231fea8d1c826an/a Heodo