URLhaus Database

You are currently viewing the URLhaus database entry for http://vrindapublicschool.com/cgi-bin/OcK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:604045
URL: http://vrindapublicschool.com/cgi-bin/OcK/
URL Status:Offline
Host: vrindapublicschool.com
Date added:2020-09-23 07:48:04 UTC
Last online:2020-09-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: bomccss
Abuse complaint sent (?):mail Yes (Ticket DCU002957791 created on 2020-09-23 07:50:06 UTC)
Takedown time:5 days, 6 hours, 37 minutes Bad (down since 2020-09-28 14:27:37 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-26Ny.exeexe b1b6231fe977d6c08140d5931af07caf65c8e3b570ddc611dd40059058e0c7fan/a Heodo
2020-09-25Ny.exeexe 952c0a8421ccde92a989eba731866c994a69e01dea13645197e485a27afff31en/a Heodo
2020-09-23mu99R.exeexe c3b59c3927b7f87bd3a275a1d5af06ff2c659a2966b3b1fd1614e77328be8ae0n/a Heodo
2020-09-23CN2Ahk5qGGblenb7S.exeexe 53d686cbf0b861dc50b83961f2967c5202da6f66a92fd003166cf1041a9e71afn/a Heodo
2020-09-23nYL.exeexe f6aad276d1fd1d218112d1539452a45a03000dd2061ab96aa48a9dac131b94e9n/a Heodo
2020-09-23Xk7Q1249jfPJD5quWv.exeexe d7266b7629c7595100c30f289c9f7de1d63a59836106d53f62cc352411dcfb9fn/a Heodo
2020-09-23QTJNrUgGXw0L8f.exeexe 2c3867dc76dacae49cabc65e53d2737fbd7966cbc1e5214c824b51958b4c910en/a Heodo
2020-09-23A58mu.exeexe 4ca0c33914210c55391300e480df67dabe8d58e7adbee10503348ef63bad2cb8Virustotal results 21.13% Heodo
2020-09-23d2.exeexe 8d6281405ab1557621da0d0f994bb7e53b8a4ffb0e2dce08da18a67db618c3ddn/a Heodo
2020-09-23SYKso7dhLhKnCtoaBeOq.exeexe 2376153ae2dbf6b1359940e10701fbd1a99fe42e9df9d22a790354663ad1e960n/a Heodo
2020-09-23KWAo8dOYcOXeXVj.exeexe 303f4ebdcdcf1dc165b24a559fd8071f3b77e7e212cec9d8151a046346a87fe1n/a Heodo