URLhaus Database

You are currently viewing the URLhaus database entry for http://rajania.com/cummins-engine/nPd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:716774
URL: http://rajania.com/cummins-engine/nPd/
URL Status:Offline
Host: rajania.com
Date added:2020-10-19 09:10:09 UTC
Last online:2020-10-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 09:12:10 UTC to abuse{at}upcloud[dot]com)
Takedown time:7 hours, 31 minutes Good (down since 2020-10-19 16:43:55 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19Dh7Bv.exeexe 060d57779e6d0654b5431d5750018335dd3c863f0539413486de3e08c1194a34n/a Heodo
2020-10-19pbU1tlu58bg.exeexe 3cc442640e398998be3024ecbc5c37c0f3f93dadbbbfcc89cb5d78d0d9aa377cn/a Heodo
2020-10-19rHuWX2QmCA.exeexe a15319b91d1bf57e812131f25b95ad0d9a776d1d52664210b67cbb57c8cd4287n/a Heodo
2020-10-19KYsmWBX2yYBG.exeexe 2281745b815560882cb3900bf11b63d7ba7cdfd2438e87f49f8659cebb35ee89n/a Heodo
2020-10-195JUnW34B.exeexe 16cb55a5c8b788fe19dbf014647bf515cebac969e07e157baf0b0b8cc9d0ea0fn/a Heodo
2020-10-19UUgRR2XuH9MfL.exeexe 236326e907d591152e76ac890bf938ccb4034337a9436c20d37abbf4e88304d1Virustotal results 25.71% Heodo
2020-10-19QxQmb4.exeexe 2edbd4ae538a0f6ddde3d42b3ecc6a5175c306ca6da03c5e93a49ef172291e72n/a Heodo
2020-10-19XBcT1l4k30M4FySU33Lk.exeexe a82839e0285918f9c6487a8a09895458cffdeec6fddee410afa0507fc61cb729Virustotal results 10.00%Heodo
2020-10-19f.exeexe 9f66595ab6d81ba9f6f907bc8e77569035f5db7eb93b91fbfee650f0b6b7e8e3n/a Heodo
2020-10-198MRevrPjzQOwLqieXG6.exeexe aeb00634456a0281e2730414683791ce68207469fdcd04f612ff2cc8a779ffcfn/a Heodo
2020-10-19dOOjmD6KAzZhc.exeexe da6e346e1877e631d154f6984998ff900baeb0a2a944a22ab62e7c90063c25e7n/a Heodo
2020-10-19d4M1tTbcL11uoNh.exeexe f2005cf990d7fec252d5ba7a1a192ca1841fe811906af93ce13e78fbaad389a8n/a Heodo
2020-10-19gVOscFAV.exeexe 634317a223cf57722ebc941ba09b7e2fa24287387546f7d6b7439d1e859efa7bn/a Heodo
2020-10-19h.exeexe 0c1196501510e4e318d7a160bf6d95e2ad1584eeb2d235c116810ce7720a768bVirustotal results 19.72% Heodo
2020-10-19jHNBdARI68Py.exeexe e1c39093ef9ce618af4647b96268be1d2330b1fda8f9834b11892d49d67ab88an/a Heodo
2020-10-19cJjhr5nbymZ8.exeexe 8f2429505e362185e58088ee315970ca4993d8b78f3a4fd8bdfeac429f15bf63Virustotal results 18.84% Heodo
2020-10-19J9GzHLaIcavf.exeexe abe2ad426f8258f3520303805d124faca4f522a3cf76e1bd9c8edd551a39a6d0n/a Heodo
2020-10-19msbSNF1LFIw.exeexe db9ad8fedb51709b721d56ac4679544b01054824fe9ee053af9e724a9369002bn/a Heodo