URLhaus Database

You are currently viewing the URLhaus database entry for http://ekinerja.megadata.co/wp-content/VFWW/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:594842
URL: http://ekinerja.megadata.co/wp-content/VFWW/
URL Status:Offline
Host: ekinerja.megadata.co
Date added:2020-09-22 08:58:39 UTC
Last online:2020-09-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 09:00:04 UTC to abuse{at}cyberdata[dot]co[dot]id)
Takedown time:2 days, 17 hours, 9 minutes Poor (down since 2020-09-25 02:09:31 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23v7zyJMR2G.exeexe 530bbfede13fdbc64958c7be23c0e4e036310e9c44615e85043a3cee3daa0d24Virustotal results 18.31% Heodo
2020-09-23pTcKXE.exeexe 02dedfc36519c13e7576578cf9e252e86508bf32791ce39ea5220e6781455bffVirustotal results 14.08% Heodo
2020-09-23cn.exeexe 42067c6f7796aa20563de80bcc372ba54f31967f387c025e7a9db470389fb9dan/a Heodo
2020-09-22ZB10K.exeexe 1b0a7a3ea4f510ed415c28cd017ee493facf9032feaf32b079b4d84aea2f5850n/a Heodo
2020-09-22m89wRz6MPihEvoITH.exeexe 297298d208567bca136ed801d60f25addaff2eacb507def1bcfe0a49e4d224fbn/a Heodo
2020-09-22gX5uOO.exeexe cef5e4ba5e53bf84f886f81eca59721bde2fc7885c85353f662b34e7f1f4be88n/a Heodo
2020-09-22Udig2.exeexe 3805f2e7185f40656742dc4d4697d80f4dfcfe942b899be33a836478ea083536n/a Heodo
2020-09-22t2ciK.exeexe abf8c06f75130b4da372d3d071fa4815cce211dffb886473b6c1ae05e93b6e7en/a Heodo
2020-09-22teWVwfdBOn4tv.exeexe 981a47858b8e01fa411134abc5a4d7c8e063d4687e37c776f6d832d4302a1d97n/a Heodo
2020-09-227yFbukrX.exeexe f24e9eda7d192aabb33a17421148234c3a486f13b6092d347207acf0d17163c2n/a Heodo
2020-09-22cl8FpcJQZkYey.exeexe 5b5c19fd89ad637a73afaef1b8d2cf018e5c6c7fc03d345140e754f1c1085949n/a Heodo
2020-09-22a.exeexe f7d47682dedb008fec9d0164820cc7b5d290beb4f6d2d522322bc9c6f6c0ab45n/a Heodo
2020-09-22WHSYUh98IAac1AaIe.exeexe 64df3aa9c11a0aad6274531467749f969b1648dbe56aa2586d9746dd7a5c90c2Virustotal results 14.29% Heodo
2020-09-22Luw2N.exeexe 4d541621d37476341ab1f1ca05b62d271752d1c746b1b8d729c2e10c678bd4e5n/a Heodo
2020-09-22tx4Godpt.exeexe 560b5637cb4c22a7cd8daf36d48395daa920c04ee6832f6b527d26054a6ab0aan/a Heodo
2020-09-22KW3urBgMZp8QzX.exeexe 2e9c51982ce5d103b100bb696b36afad9e237d8016b68d89269dab8022f13440n/a Heodo
2020-09-22F7z.exeexe fe489c69fea0fc9b58f937c4096d45d850ead38f448f9cc1b02b9e7aa4d244ffn/a Heodo
2020-09-22WSunnWC1og.exeexe dfa83ccfe00fd425c31ee59edeb6de0392c02d631ef31d0c3c6477e9687bac51n/a Heodo
2020-09-226gN0uM6.exeexe 1678a0f8469b493a6785a4c26ee2c2c6b65e9eb6be40db376a7813c815041270n/a Heodo
2020-09-22yokLYvR0t9x4IB.exeexe 6939000ebcd98b4ea38fbbd6376d1b773adcccc4d0792ccf9c2ae61ee306dc30n/a Heodo
2020-09-22ZXxNidAvIg.exeexe f80c81a44b1feaaaaa997a5f250b81a68cfebb4ddb4b8f0203e358b66f1b1a39n/a Heodo
2020-09-223EXVIk.exeexe 743741dbad812e0b29bc7ef18b44ac427cd461551a9d3a32cc3312a7c0fe5987n/a Heodo
2020-09-22NIasGjlAQQeB.exeexe 30e82a1ed2c9cc6a184cdea193536640472b2462eb7efbfd6db75cf9678c7da6n/a Heodo
2020-09-22H.exeexe fcd4b7e597b44ac433fa19ca8cc74857edeb6518c006d48821d2553ee5762285n/a Heodo
2020-09-22CMiCvHCoGR738.exeexe be3b4785665752536146ef7ecc1676d00cd701a6819d921d6ab17cff57909ff4Virustotal results 12.68% Heodo
2020-09-22c1dR8.exeexe 3ab4d7c8141b9631b259369c016aca93b196fcb6931011c2ba53673c454b793en/a Heodo
2020-09-22qq3vU.exeexe 9fd460bce4e8fbad452130274a453d5d15403a8d222c0a5d79a6a21f4bfab98fn/a Heodo
2020-09-224pv8BqOMMu30UIVY2sZm.exeexe e5f29637cafaa4e3eca750834cbdabc69b9a3ececf64a70ad86742317a4fb089n/a Heodo
2020-09-22Bk9YdiOo.exeexe 59c54ff58f81843e733d850fa28ae602c91511a5f42af9151f6a7f723798dd16n/a Heodo
2020-09-226XguakvhtZNUgsZwW59H.exeexe 00ed9e2613276fbdda6a5b5d015043ad653908a230242128351af97e735a7184n/a Heodo
2020-09-226xAVI.exeexe d4d69071a96a51dd1773dfe509e108a212b8067f679a509e0fb4c8b5344ba39an/a Heodo
2020-09-22zCBdQQAWmW4W91Re.exeexe b55a77ecd7e17072e4f16c35eb2d08c3e171e07da6cb4da3d4fca7bd02f0f833n/a Heodo
2020-09-22iQVXaS0c7nBUAoQ.exeexe 2f2aed1d637f3432867009d5ba45d4e226404fe11ce4bef4d01e95ea3693f20an/a Heodo
2020-09-22cs0TC571JWXYsAvq.exeexe 6065196dfe41b5e2c1792662071707d222b24a734a9f753cd2d7ff38d10b4e08n/a Heodo
2020-09-22pAz1tz.exeexe d5b1b54e68b2e100dcdd7bd30e6d1f1412cd717c85a6bbeecb9d58f7c7462b37n/a Heodo
2020-09-22L2WJj2XHrpjmOvVtqw3Z.exeexe a210b38f78d68abe44dc35906ef9b5d2ada478ff8a9995d20b6125967dbc181fn/a Heodo
2020-09-22xkMOLb.exeexe cb97aa92beed4c5b6e7716518579417572a74c7c171df72c0dc5fe37bf6e12e6n/a Heodo
2020-09-22ijuWJK7f5wF76BM.exeexe 8ee47a7dd100498751868f8e1751295eeab4436d81695d5596b7d3023ae14e70n/a Heodo
2020-09-22IGxdMR0t4hA7rEqDXYt7.exeexe 410fb96b3ec7d0e5b63ac89a687ead92eb487475ae275ce0bf8495568b156129n/a Heodo
2020-09-22tKVWUZbaYXYmiHr.exeexe c7f1ceeedad73f7eafe61a6f890a4341cb2248018f0821c89220d97214dd08d2n/a Heodo
2020-09-22QJK.exeexe 45a28d210d1ba0c84305fedd3961faf03b9c170555de8602289165ad5e9e7c9eVirustotal results 18.57% Heodo
2020-09-22K5kd.exeexe 3de0065a5549f4823cf898d00aa28713f78bb7c0f1d158c7187b5471a0c06363n/a Heodo