URLhaus Database

You are currently viewing the URLhaus database entry for http://cnaantours.co.il/wp-content/VCsDu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693125
URL: http://cnaantours.co.il/wp-content/VCsDu/
URL Status:Offline
Host: cnaantours.co.il
Date added:2020-10-14 15:43:07 UTC
Last online:2020-10-14 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 15:44:11 UTC to abuse{at}upress[dot]io)
Takedown time:5 hours, 26 minutes Good (down since 2020-10-14 21:10:52 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-14QOweIaVnduE.exeexe 44b772de57aa08e1c305f5effe6f99813dfe355654118a14cfff849870148abdn/a Heodo
2020-10-14N6Ab9.exeexe 7c41266fe74c1fe54f365ea7c04fe7715b69ad96b4e67cc0dfed7fa718fb97c8n/a Heodo
2020-10-14Co.exeexe b2a717bd9b4a3de43c99effc6cb8c48a336100bd45adcc7a06631fa1ea034a18n/a Heodo
2020-10-144.exeexe 8826db692c3a0791d966a98c09d8cb0447da60bb43af5d14d8ab0fdbea248928n/a Heodo
2020-10-14F3qJjpgKCtLoy1AjxB.exeexe 8c0860bc9eaab6eb97b846295e1a02f6153eae6cf7d4f6d8a247994ca39ae67fVirustotal results 9.86% Heodo
2020-10-14CCHIz3d6eOGM9yygbT.exeexe 5a43ec465990af764d47917091d06ed8a59b774cc609f1e872832eaf60b99871Virustotal results 9.86% Heodo
2020-10-14J6BG.exeexe 4bc34ce0d433500dee3b3896064b60f0eedad3f30093a065f626e13e92f3e0c4n/a Heodo
2020-10-141K599rZ.exeexe bf18f505e8e2f964f4ecc495d2daa457bfb405f24608ada796f24d9f2a1e84a7n/a Heodo
2020-10-143u.exeexe 36b052c1a71276af4671f95666fdd6486f0c26c847a51d5935d1c8bd1603b59eVirustotal results 8.45% Heodo
2020-10-14OokIG71ycoQSygME.exeexe 170c098c50f017770433436948ca8a8e1d345358a9740edeebc7f1afffbda6e8Virustotal results 8.45% Heodo
2020-10-14ZEhGLzVPoH.exeexe 56cdbb149be122f0ade197af2d66d0d9ad08467c3ba3ced8780a3d92095c8215n/a Heodo
2020-10-14XT5bE.exeexe 755fa34a00ab1f07a6ce7c64b7d43f205596ba641c2e7987a97d05413382568en/a Heodo
2020-10-14NFiiqQUf.exeexe e7969b77331ce728d08551304aca1006b5f98759123df8ef8ce9a2a1a4ebd64fVirustotal results 15.49% Heodo
2020-10-14BXay1L1U49asurp2xV.exeexe e99758c1786eebe797ba7749ca685b3b305bbc2432db28d4c44f4b2283d5bb78n/a Heodo