URLhaus Database

You are currently viewing the URLhaus database entry for https://youxel.com/sys-cache/lLWGgV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:622365
URL: https://youxel.com/sys-cache/lLWGgV/
URL Status:Offline
Host: youxel.com
Date added:2020-09-29 10:48:04 UTC
Last online:2020-09-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 10:50:12 UTC to CloudFlare Anti-Abuse API)
Takedown time:5 hours, 33 minutes Good (down since 2020-09-29 16:24:05 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29c.exeexe ed0fdb5d86695a76430522f6e109f20635a8d44f860d9985d6f900de370ae8ceVirustotal results 7.04% Heodo
2020-09-29w2ERaeJgWR.exeexe 2b42a086f803be928c931ff28fbb424de25406181f1141b659cea5741aa58825n/a Heodo
2020-09-29J17O5RLI8j61dYdoIB.exeexe cf931dabd97d69e0d6dc4b3489f417ebd8dae4dc1d38caab9f7dce983ba2a09fn/a Heodo
2020-09-29LdHxmnNyySynS2TLzL.exeexe 0c93e1f7975adb3d4e9148ba54a7f2cc0262836a22a93e96fd84da0088e83678n/a Heodo
2020-09-29hKrFjWm8lQ.exeexe 32dbdd3b856bac93339baf9d657b630c3e125d2628b49473494e78e166103b94n/a Heodo
2020-09-2921oPutr4.exeexe 2dd401882f449e7bc848a37eb56288792bc7f7bacda2c5dc98f73d310494cce8n/a Heodo
2020-09-29FqXB3wxNC3rOu.exeexe c3078808c070765a65fc2b81c28e5253bd3713f31660cc8eb6ef388636d42107n/a Heodo
2020-09-29De.exeexe e13781ac612c6b81ab90f8433cacf7584b20b96c0eb29847b3dfa8045ca3035cn/a Heodo
2020-09-29cNNuWcg.exeexe 39fd032bc86e39327cde51a4194afbab81605a2fe4c6c136bf596ebcdd698d48n/a Heodo
2020-09-29gBAb.exeexe a17167c3fb352eb16f4f728a59066a57510c6f8482b911479b5325a5d8c7c1e0n/a Heodo