URLhaus Database

You are currently viewing the URLhaus database entry for http://megasolucoesti.com/R9KDq0O8w/Y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:605369
URL: http://megasolucoesti.com/R9KDq0O8w/Y/
URL Status:Offline
Host: megasolucoesti.com
Date added:2020-09-23 13:02:34 UTC
Last online:2020-09-24 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 13:04:09 UTC to abuse{at}hospedagem[dot]net)
Takedown time:20 hours, 50 minutes Good (down since 2020-09-24 09:54:47 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24VDdKs1qOOh6sl.exeexe 0a0bd0adf1977f151ec10c31cc190caa9fe8b420b131d86c5fea3ff05a475a74n/a Heodo
2020-09-24XhlJG.exeexe 28650ce9f903874cf13530c8c78325be6cc411faaa41d9f22c26c9bd2c3e8ca1n/a Heodo
2020-09-24Ji0WWZsOtDhi1BCUDd6S.exeexe 1122ae7cd2d28bf8d853ff4c93c9ca4a978442fa39b72795becc0ae13cfa6027n/a Heodo
2020-09-242Zg4BeNnvN4QLqZgY.exeexe defbdabae1620a3b6d413028b38122e5a7967ce48a2db906756aad670ca060aen/a Heodo
2020-09-24FGI.exeexe fbf49bfe8edd2f541dc0b92847af329ff8f76869a8b46164ad15b9d9a17a0254n/a Heodo
2020-09-24Vz3681njBnf4J.exeexe bc1e8d7003495a0b65cd368243347f219376b30eaa88031adc113ac34c85cfd4n/a Heodo
2020-09-241FdxUxPZ7Wo.exeexe 80f8945c742f3e25d7cad71ce38a8c253d9b2c93509e97f4484b929f297677c0Virustotal results 30.00% Heodo
2020-09-23IKc5ki6.exeexe 89a8ec0bbc95e3fc27832147852297a6812b1e429a7a5916ca59b1994c9d92a8n/a Heodo
2020-09-232qcXY7PmEyh9KQhc.exeexe 06c887a53c4294d0e3ff1552457597940f3afc377217599bbfb5de37cf59f7fan/a Heodo
2020-09-237XYx2SObFOmHmufwux.exeexe 418cc82118c3ab4a5a48cae81357d90f7beef3122c2693289475bed2c39a87ddn/a Heodo