URLhaus Database

You are currently viewing the URLhaus database entry for http://bitbenderz.com/ali/4Lo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:604123
URL: http://bitbenderz.com/ali/4Lo/
URL Status:Offline
Host: bitbenderz.com
Date added:2020-09-23 08:00:35 UTC
Last online:2020-09-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 08:02:03 UTC to jcdmacleod{at}gmail[dot]com)
Takedown time:5 hours, 12 minutes Good (down since 2020-09-23 13:14:15 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23FmQuNPrmNsWvYt2.exeexe 871568318bd38275552ee950fe6523d8560a7125aea11a539af1ee23122dddd5n/a Heodo
2020-09-2304Q.exeexe 910db82656136136a224893253312031aaa1643f0dcaed69dec88d286f2aff8en/a Heodo
2020-09-23kiYojZ.exeexe 792b2e4f52042df7c9950a09b969d5721b8363d059ad8f5069a769703d05d876Virustotal results 8.45% Heodo
2020-09-234bHs.exeexe 658f0ebbbe7b26c0da1e677be9fa0c721203f158d71ada6f7deb513ea1f1fd67Virustotal results 9.86%Heodo
2020-09-23TfV2eL7V40PwDYLJawRQ.exeexe a0efa0a96ccf9f4b73edc6cb75e3dfc750624da670b69c22aa94bba17c11a708Virustotal results 26.76% Heodo
2020-09-23DVKJj7NAiw2q7qFgtz4.exeexe 76ecb4bd1378ed27541dc2b8f74f60f02749296f44f65f29f3d27e49d9d492cdn/a Heodo
2020-09-23uf3vqA62wUamjCtxXWi.exeexe f073c89a2ee6f78cf69de70dd8ed82caa0b2a0a0e2399b7757b8ed569a33e59cn/a Heodo
2020-09-23DXZ2ESbBWh.exeexe cf9bbab84b62b531991769d2f04fa6a78df062c0b4d93c62c4404ceb9bc28970n/a Heodo
2020-09-23AMYqBHCwCF.exeexe 7ea592ab614704958df61df11f83ba54a2b2a865bdd4c63fde34433cdf284fa7Virustotal results 21.13% Heodo
2020-09-23xy2rYEvEEZWa5.exeexe e46672669d971d685c2fcbf2f19f75e60eae5ec5f4752bd8226c10dda419ddc2n/a Heodo
2020-09-23fePSAXW4WMC9XLTvgYf.exeexe 3810b1c4f995ccff882466d5ed994c4090148f689eacb37837a0620a1ee9d19bn/a Heodo
2020-09-23qLLRw6TJGc4fxWjka.exeexe 48a740e9045f34de6d6e80689ee15b8b68de51368129f6196888d7531e066c4fVirustotal results 20.00% Heodo
2020-09-23QabTikdEl4LLHzr1ylgq.exeexe 025a9ebcbd34e257bfaf3dd95c472b9a28b49e97fa0a7502bce4641abe1ce294n/a Heodo