URLhaus Database

You are currently viewing the URLhaus database entry for http://djeffries.com/zdLepG59jB which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:58558
URL: http://djeffries.com/zdLepG59jB
URL Status:Offline
Host: djeffries.com
Date added:2018-09-21 09:44:08 UTC
Last online:2018-10-11 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: ps66uk
Abuse complaint sent (?): Yes (2018-09-21 09:46:07 UTC to abuse{at}godaddy[dot]com)
Takedown time:20 days, 7 hours, 56 minutes Bad (down since 2018-10-11 17:42:20 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-28cE6ahjFYJyAa.exeexe 8f305c76653814ec0fa14efd2905080bf5a0b038097d85fe457e67dcd5b53ea4n/a 
2018-09-22cE6ahjFYJyAa.exeexe bdd8a6663cf2119d27477a9c2c78f54e957fe757520a15aa6937137d10895814Virustotal results 15.15% Heodo
2018-09-22z6gfvwnmC.exeexe 85767d8110c0e3f54197612cbb73fd3c12c4e24aea1d20de00535c497963fa6bVirustotal results 16.18% Heodo
2018-09-224vH0jxZkgra.exeexe 2cab9c75735494828fe07c3e8c5c480ec0fd6ae6fae4e7899b38e9b5ec18b0fcVirustotal results 13.85% Heodo
2018-09-22iKDVyS9LAgm.exeexe 4d444847456e7c86d11473c5260cac9390487064f87d01308b6b393de636f2b7Virustotal results 14.71% Heodo
2018-09-22q0HGHwgI49kg.exeexe 3f97c69ef86943ce56e117c3857242277f34aa10a4d9a3ac33329ecbd273e1eaVirustotal results 15.94% Heodo
2018-09-21pQehNkIQ8tFL.exeexe 7cdbb8e6de99cfca3923d3281a6c594c918578f6b6065e98ae5d8971a45e2f7cVirustotal results 26.87% Heodo
2018-09-21Ur7pNvXv.exeexe 86b3ef778ac613b5543644e3c79ca742c415ff55b68cf608ff3699382d55b3f7Virustotal results 36.23% Heodo
2018-09-21eeXXyjER7.exeexe 9acadbc33cb49d93ecfebe698fa8c8eec94a695f7603d330261da8c5f36ede89Virustotal results 27.54% Heodo
2018-09-21NWwn5YuZ.exeexe 48fedd8eb8fd95b1c3f3a43fe0ed4ff6e769902b1b7db1f07953455b5ff2c662Virustotal results 34.78% Heodo
2018-09-218OhwIGTYo.exeexe 43bfad2b7eb0858ee67eb8649a2661985fef721e05cf42645c262ed1df69125aVirustotal results 34.85% Heodo
2018-09-21WluObomEPA.exeexe f34c9ef95c6c2cae232705e1209db9d828d2862d056aaa47213e6c1aeea10f6bVirustotal results 40.30% Heodo