URLhaus Database

You are currently viewing the URLhaus database entry for https://pfcnews.com/wp-admin/xN2fu7X/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693972
URL: https://pfcnews.com/wp-admin/xN2fu7X/
URL Status:Offline
Host: pfcnews.com
Date added:2020-10-14 19:15:12 UTC
Last online:2020-10-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 19:16:13 UTC to abuse{at}hivelocity[dot]net)
Takedown time:18 hours, 49 minutes Good (down since 2020-10-15 14:05:27 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15UcNrczRvB7z3y0.exeexe 05507190291045d772dfb92a5ed6c887261b73e6b68f4d015c0dd7876fc8e30dn/a Heodo
2020-10-15BXwB6jstTyzBmoShueV.exeexe 00ca99b6513b9eb984e97c7b08b848c39169e61e07e82ca94823a589bed46d28n/a Heodo
2020-10-15Rk2kKGpX8K.exeexe ad3e117d0a00a63711b6276b7b25f5d0c92c574c7d23d5d56193a7ea9eb21846n/a Heodo
2020-10-15gxoruqmG7vLjrU.exeexe fba4793069fa2b0c0cb9ef94f21d6c3322a16662784fb3f382e6a7fd918e03a7n/a Heodo
2020-10-15jPRydoMVJ945ENRFI.exeexe 2dda4187e5cd85d65731eddc1fd67d51ba13f8ad0dfd45e195627158c6bfa12bn/a Heodo
2020-10-15wJpLNFJuqqM.exeexe cd22a1d9d67a96f4bf70ebf26061ddc9e051cf33871e24cd8594d93379360a3dn/a Heodo
2020-10-15DTOwCEPAm.exeexe b7cd537acfa07e75f7de34e8ec27ec59dbfb41437b03950b018239c6667bd15bn/a Heodo
2020-10-15V6fxGOUEQu.exeexe 4d05e21188191e0b96fe78f0016105808820720b4e34569335949bf92c0551a4n/a Heodo
2020-10-15XbQ7ooWmYftjf1CeO6.exeexe a12c69ad9f169ea8ca46be9eb7a0e8d2e6a7be4d490e5c84134a8d9c3c3638e8n/a Heodo
2020-10-15VBUOU2RveB33BR.exeexe ad695f7bf9aec7d55815bd7e214b27a96cd4be96117094b8d07999556fc1a4ecn/a Heodo
2020-10-15s1EnlrptbQmpVjD5.exeexe 127ddfb309ee195f0c4a39ab6c063778d84ebad14a72c36ae6d480cdb0c397ccn/a Heodo
2020-10-1501GucSrOnyI00o.exeexe c36471d7004fc6aa6da8ea83ef627cb83de6e67b20ec0e2c31a4d88a073f65c4n/a Heodo
2020-10-15KDWjpa4OHRx.exeexe 53e740760cef3c5abdeb569e2be5569a3514749d7c9c0c7d713445981ad694b9n/a Heodo
2020-10-156e6WWd.exeexe c1bf9a67c9d6058bd0793ade019394d1a3646ea8d86189b1a2cfb15fd1636ac5n/a Heodo
2020-10-1534u8x.exeexe 6b0a968d49224a59039d7a97c1511dd010d14545fb10092b7da32b03be7f31bbn/a Heodo
2020-10-14a74U.exeexe 19bb0fde80e905414b0a50c2b9a21d2c0d979a3e06b402c941e7466d53b57a32n/a Heodo
2020-10-14NC0EUvx.exeexe 55585060b13f5a1e668c325475020aacca1e9d3596bb056ab1588ea775310c19n/a Heodo
2020-10-14waqaI9k6ao3aNH.exeexe f51f3185f611d9b8d92a48b94af0dd45cf09d00d0b401ffc8dcef8d110fb69den/a Heodo
2020-10-14k7lR4J5jAX9tZ4o.exeexe 3c0a1c023e0ac49be84455b898727601745b43ed4f5a2691b3abf3011aa438d5Virustotal results 11.27% Heodo
2020-10-14nVxbWOy4paP.exeexe 801c75175e841e22e4774d067304e131d33078b9c843e8638d67fa4980c02391n/a Heodo
2020-10-14OI.exeexe efb02985f68279866f226ce31eaf5243eac4e8b84a59159e4dfae9be8f899409n/a Heodo
2020-10-14LUv.exeexe 27e85a9d8c347b78e38417cc69b0cd472861434009c82861d0e2defc78a3609aVirustotal results 8.45% Heodo
2020-10-14kb6RUUEEjUSMuQSF.exeexe 7b277f6238a5c7139e1821ba50d19119e732cc80604cc68d319a52730eacbc13n/a Heodo