URLhaus Database

You are currently viewing the URLhaus database entry for http://winadev.com/uglot/iiClU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:585934
URL: http://winadev.com/uglot/iiClU/
URL Status:Offline
Host: winadev.com
Date added:2020-09-21 12:34:06 UTC
Last online:2020-09-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 12:36:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 27 minutes Good (down since 2020-09-21 14:03:26 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-2152siIk8BJYzf.exeexe 99abc0ddd4dc5f4915e6516be55a0b37e178dce4e5424167f76c38a8d8fb935cn/a Heodo
2020-09-21zz8j.exeexe c9383af5c6af12ae13072bb41b22e0ad23013c8394f3ed9b5c105db16fda9e30n/a Heodo
2020-09-21iQVPKVpLARcL0M.exeexe 27f320eb0852de6ebe451a209197d229a05d5c797ce49d081508567d1bf779afn/a Heodo
2020-09-21QLf.exeexe 303da7434ff818c11f9bb531ea58137abdaa451a5a4e3f41b483cdddae55b6c3n/a Heodo
2020-09-21khibPzrzWx.exeexe e4e46bc59f630c7a659add7d3489a4366aa7769eb99d9d00a840643987ab7077Virustotal results 21.74%Heodo