URLhaus Database

You are currently viewing the URLhaus database entry for https://unitedway.giving.agency/sys-cache/XnT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693965
URL: https://unitedway.giving.agency/sys-cache/XnT/
URL Status:Offline
Host: unitedway.giving.agency
Date added:2020-10-14 19:13:06 UTC
Last online:2020-10-14 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 19:16:14 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 hours, 29 minutes Good (down since 2020-10-14 22:45:25 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-14Vk7860aT3DlPlTV.exeexe 59bdfe14e9032cb2801c1a1ad406e9f2fc8ec2cfb5983ac9d42e96b8041befd4Virustotal results 15.49% Heodo
2020-10-14t8YObcqXq.exeexe dc236aa388ecc5c8f2636e00f30680072b44eb1efd98c65b7b0f527b3b974567n/a Heodo
2020-10-14lf7c9.exeexe f332751ae31142993d88783d2d3621ae8361c9344b7794932e5919dbca89439an/a Heodo
2020-10-14t4Fr89E5.exeexe abecfd4928e3332040517dbc2d5dcd5d14a4f3d12c1249ac45a4eef2c7f491b0n/a Heodo
2020-10-14uUxiM8tcmnvk.exeexe 73db7f1e2395f8ca4b3c28f26e245c31fec4cdf9d6e3f397635aa10a87827430Virustotal results 15.49%Heodo
2020-10-141iccICAwQx.exeexe 3af0924220bb7b8849831da1c36662741f8b4d106fa34461de6b638ffaf064b9Virustotal results 11.43% Heodo
2020-10-14HkC0i86U82KUITB9M4dT3.exeexe 2041a2852108ced2940bfa48a7ebc09a662e1fc21537ea196308a93fa78cbb47Virustotal results 9.86% Heodo
2020-10-14lB4DIGi.exeexe 2d6143ee7a8767067c0ffd79fd618b2d0cf2454d0f136620367a2887a3dcc2c0Virustotal results 11.43% Heodo
2020-10-14tBWu9hz6cYTjCX7.exeexe 5cac6b5bdc8e73ff752737ab345c35eb7509847418e40c6c3036d7e151530150n/a Heodo
2020-10-14KXBTbbV1s2.exeexe cdac708aa01dddd62db4a7154010a4964350b8a0afca3555bc82b512d5787db0Virustotal results 14.29% Heodo
2020-10-14MTIteI.exeexe 3d974e415c4554e6b0fb3484fd3adee6db08f93842b26e1a0d9c9f0d96fcc775Virustotal results 11.27% Heodo
2020-10-14Z0RFwHUI6gOqcMSNwl1lv.exeexe a86d1cadaaec91228d4f85dee02a88c669f6847dde815128a59d79d31abca4e1n/a Heodo