URLhaus Database

You are currently viewing the URLhaus database entry for https://help.hizuko.com/groovy-count/iY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:717582
URL: https://help.hizuko.com/groovy-count/iY/
URL Status:Offline
Host: help.hizuko.com
Date added:2020-10-19 12:09:07 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 12:10:27 UTC to abuse{at}microsoft[dot]com)
Takedown time:5 hours, 57 minutes Good (down since 2020-10-19 18:08:18 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19lXBqGFgqhGQ5Zylj1uz8.exeexe 6031b8976d845ef1c31a10a0301a4f79ef6271d20bdb22cdfd12c67c7f02c124n/a Heodo
2020-10-19v8V7xxECeBEu3oS2dBf.exeexe 23153f6ddc17babbf6270a8b55a1e0ed9bb4f706099ff79c80c44d4c11963a41Virustotal results 8.57% Heodo
2020-10-19jW66DFmqdd25wWvfOZZ4k.exeexe 7f515fdd33ac7cb41d4feb82739ccb3d9d828bc821bc63948fda89cd62bdf545Virustotal results 8.57% Heodo
2020-10-197z8n.exeexe d1ecfde47a026a0d8496026d51f2c7f3ac88d7fea8558072a5de832d24fe5c68n/a Heodo
2020-10-19A9ZDX7wTSRTtApTyA.exeexe 6abf817c4a1cefef0143501322810bed43d93631fb34d44985b27a2c3382265en/a Heodo
2020-10-190jV4Ge.exeexe 4aba7fc00a0f5a54c896dde0529437e739874b43531ae6174f633c9d21eb940fn/a Heodo
2020-10-195ME6lDnCAypQdwLP5nJOY.exeexe 24f043508009bf0f6d494b892e2043323634404aba91bba254f14395cfa90f2eVirustotal results 5.63% Heodo
2020-10-194oZ0PTKjGj8sMkz.exeexe 0fb83b8acf39435e88d1bf8e6bfe3893a080aa34ddae24ee43955cc79a4b5bd2Virustotal results 5.63% Heodo
2020-10-19BQ0kwD7qgN4WpBFmw8H4.exeexe 575ec080d786459a087b745269442e773fdd4802ca42ae5f147f20d1698ccecan/a Heodo
2020-10-19RSuQWFki1xfQ.exeexe 4efa31dce68be1c7a63fd11738d224b62c51c7867079f7ac3f83419a5d133d8cn/a Heodo
2020-10-19UrEzo9Xp.exeexe dc3074a92c6d6db4469c3aefa6c8dcd0dea1c449c35e6a8d788dc9bc42801637n/a Heodo
2020-10-19g9nhitwwliimDlIZ3UgF1.exeexe 323603738df556d76622ad0e037364793aaccad09789eb80b247006c058674den/a Heodo
2020-10-19cD8mfooinA2U7u.exeexe d37e2566337cf7db978aec9369f90c659bf501d2d47528279566bc50f7aac84dn/a Heodo
2020-10-19cCtqJS36uFvAfHfly9kR.exeexe 814d2084dec411e7f52fdcd1bd6bca376b3710245b7eddacf939f6b69570f2ffn/a Heodo
2020-10-1937S0DhwrhDpifj.exeexe 33ee7efb2dbddfe1e5722a450613455d5584e777c4d0a92fbb3fe11faf28d8abVirustotal results 9.86%Heodo
2020-10-19IF37kE.exeexe 67b35907efab1fc65f397e2e32280489eb9034d07a0f2f464ddf0d3465f936e4n/a Heodo