URLhaus Database

You are currently viewing the URLhaus database entry for http://rootsroundup.com/css/n1xlBA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:601918
URL: http://rootsroundup.com/css/n1xlBA/
URL Status:Offline
Host: rootsroundup.com
Date added:2020-09-23 01:39:05 UTC
Last online:2020-09-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 01:40:03 UTC to abuse{at}idig[dot]net)
Takedown time:5 hours, 48 minutes Good (down since 2020-09-23 07:28:20 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23HrP.exeexe 42a0335876f45a317ef5ae2add65a0b66f4464833d7f31e3f623cb098b21405aVirustotal results 18.31% Heodo
2020-09-23aa.exeexe 257d270564cf12b6a1fb0a2736a31c6f14b8841d61b771d830a5a5b6de08eb74n/a Heodo
2020-09-23uOv.exeexe b5ef8a3d3222312943776e5fd7a2c5cde218406bd96b168286ae91245f1702b3n/a Heodo
2020-09-23FrO5oPg1iLXJrMi.exeexe 1e4714b75e4adcde120bdf49ff9c60b0f64a675bc8398af1fe3cf8d9b09cdd27n/a Heodo
2020-09-23nnENyOSiUp.exeexe 2ca3917a34dcc7d10a03b30a849a26cb476327b557932d5378f565f93a676694n/a Heodo
2020-09-23z6FCzNfTRvNafboP3S.exeexe df822024b13098fb2c206710f9b52d373d1c2590cd7b678cf6b6d699c0b090e9n/a Heodo
2020-09-23GiH0Z5yg.exeexe cf01b64fc10d69d6cc4ca7264c467c4c237bfbaccf75837e75266b49120c4489n/a Heodo
2020-09-23dMa6nOtWN7wa3aWveeqa.exeexe 23ed40232d90793d14c56c32d5d9c29cdd83afd9e6222a8401735f6480506867n/a Heodo
2020-09-238m5rpZ51iVF.exeexe c5ef17dfb5d21c8fbb457bf54dfb129f366496e322a56b5593a88db10cd5f878n/a Heodo
2020-09-239vyBbEAN.exeexe e07cb661239b00218464db37ec8e868f343eeb0642ff6ff96d6060b78d533e5en/a Heodo
2020-09-23twSz.exeexe d8e3ff98814cd07e8e5d1b619509befeeb5134440a3a61f9dddfaeb6f1667daen/a Heodo
2020-09-23cp88aoG.exeexe 5e6fe7f241d391a4d3642347b1e26c5c13ba10322a37f4eb8ff243ee694b492fn/a Heodo
2020-09-23GzI8aRUzsJ022Bgq.exeexe 885cf5530b4bd037ddf1cd320dfd883859b68a2e11a8ccb3fb72b8323eba27a0Virustotal results 14.08% Heodo
2020-09-23iTTy.exeexe d79248e1fb65320a24d45bd405f69173a1be0096c425e6bb706fbf8dec9ba6a3Virustotal results 14.29% Heodo
2020-09-23ZgT8DDP4maL7ANVzP1.exeexe f8d7e0d8f9c527285e77cb109393576fde723461045f28c858c89e9cdb201a92n/a Heodo
2020-09-23XvS3BcA.exeexe c97982a5a3458760bfd09217a3dc1bef79ea09e350010c12420cdbed08ead04fn/a Heodo