URLhaus Database

You are currently viewing the URLhaus database entry for https://arifulhuq.com/wp-includes/ucV8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720285
URL: https://arifulhuq.com/wp-includes/ucV8/
URL Status:Offline
Host: arifulhuq.com
Date added:2020-10-19 23:08:12 UTC
Last online:2020-10-20 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 23:10:23 UTC to abuse{at}hetzner[dot]com)
Takedown time:7 hours, 30 minutes Good (down since 2020-10-20 06:40:35 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2001Lq.exeexe 33c4d63ed4b968d1920f8583b89faba61a8daba746d8df4882df0cf7b096531en/aHeodo
2020-10-202CxZN.exeexe 72d62a1eca77572f7d05f2701f9380ca7b71df3e9194a66e8222ed4d12f88cbdn/aHeodo
2020-10-20s.exeexe bbb5e9122141c59f9bc286cb69d63ca0c73867517a05edfb5d44430027a6bb36n/aHeodo
2020-10-2060j8arRjZg.exeexe 9e77604537b6168bff183bc58ea7b3ad91f3b5794d5f54da31612ec5db6fe4abn/a Heodo
2020-10-20KZWfRQuqG2DGln.exeexe 29b997ee482cc7c4fde48d5768e77543c78b92c57880bd1512d32155ce727a10n/aHeodo
2020-10-207VU24RF.exeexe d6cc9eea946742fa41507654efc3055bce02c1fc055653f769ebda7b0f06710fn/aHeodo
2020-10-20yyxF5WL.exeexe 0d7d28de75419f30c07c088f8291063d4ce1b915e8e4f0030f0989940d8eb856n/aHeodo
2020-10-20k1OsjEPlhOmRRK4rBsV.exeexe cacc8f95f0c794d9a2db9a27f929a703fc3a04b605fd6b989b0808c2d25d6d2en/aHeodo
2020-10-20w.exeexe f4311fac9da3a2318fec7f6ffe74819056306a73edb18b22f1bd8e655a4be9d3Virustotal results 17.39% Heodo
2020-10-20kthhOkuiFFDc.exeexe 7cc3fb0e1e850eeacc6ae1af17e193f8b4c376d0015cc78172dcd134a4a50eabn/aHeodo
2020-10-201PsjtCdhAHp67w4qzGe.exeexe 1336ada6c97b85feb4c5db87c00b08f9b9ce4e5bc073cb84d683bafd28434557Virustotal results 14.71%Heodo
2020-10-20TFh27KIfQKXSF.exeexe 324ac28fb46f65461d78f0f68effa53d672287b251af74c8bf1c3e8fc9702969n/aHeodo
2020-10-2092zSayemhTAXeDY.exeexe 24ac8b4f1aa9286abde302a4bec1e1a3a0577b6439a010461848b3efc6ab3e4fn/aHeodo
2020-10-20uyagpQ6nTqygaaZl2DV7.exeexe aea7f620304220006407b3135c3dbf5e9c8d38ed833bcba345486fd8b4bb3a7bn/aHeodo
2020-10-20DbKf87SO5QD9T.exeexe 9f63f4d33b3f96051ccfb6e2ded39f38578608908862e5d2f83535962fc4b694n/aHeodo
2020-10-20uMTiS1J3gNRH2cYJHfn.exeexe 58ea035fa955f7e56655dde445cb215dc056f536305e7d1f814fc3d841d976e1Virustotal results 16.18%Heodo
2020-10-20sZRoQPVgyZ.exeexe 8954f8524fe22cd86efd7279b0e55b3a9a3e243bcf950256ad1704c7154b0f9dn/aHeodo
2020-10-19uG8pSKtUqj.exeexe 3eeb0379ed4f8271636fb0d8dbb51a2ae3c8f97bfe9c8b384969ad74069863abVirustotal results 16.90% Heodo
2020-10-19hu3lp5eb.exeexe 8f36545a5734ce2125389cbd9d3cc7920046f19f9c2bd3d720eb00fbba4d5197n/a Heodo