URLhaus Database

You are currently viewing the URLhaus database entry for https://theusmansaif.com/wp/eVinc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720289
URL: https://theusmansaif.com/wp/eVinc/
URL Status:Offline
Host: theusmansaif.com
Date added:2020-10-19 23:08:15 UTC
Last online:2020-10-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 23:10:13 UTC to abuse-team{at}tier[dot]net)
Takedown time:13 hours, 51 minutes Good (down since 2020-10-20 13:01:43 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20DKWSNmBrJE2HGp2.exeexe 9310b02279ab6879eafa4ad9e04c2c7b7071931719296bf1aba752b824551f6eVirustotal results 17.39%Heodo
2020-10-207OL83Wq1MUGwWg2sP.exeexe 0138a30a524681907139927620e0a2f3cdaf5c967af5656282cc1c01945db732n/aHeodo
2020-10-20fZF.exeexe b061ef352c490e007c2ab71e4722b48391b29b3094008514f0db127cc709bdccVirustotal results 17.65%Heodo
2020-10-20ql.exeexe 4541bb2e628652852c00eae74550b12d9670fb5476e7524c5c6036465a8b0715n/aHeodo
2020-10-20D0LQ3bLJzL04KvoWMm7.exeexe ae500da4529173af660fc298a3286429b423ba522a0b5550b8c20482926ac0afn/a Heodo
2020-10-20sin60uiyAtBWoXO.exeexe 2af2acb67c02574e25a78665061c16dcccea88f0327e01cedb5b83a2f33bcf68Virustotal results 17.39%Heodo
2020-10-20rIu.exeexe e453b589acb33e4c43b9be923e96c0f6a9b99b49e40aac8bc78c5e913aa0bb5bn/aHeodo
2020-10-20Mu23abfGLzjt.exeexe e796f2226782af658b67d8dcbfd1d4842fc7d0192e4a8960f930a9028477392dn/aHeodo
2020-10-20jvYabD1yj8T8NspQ.exeexe 8fe9cf9920f36a6b03cf3a7682aae70472b6b2972a52b15c7fa35d51df2b4818n/aHeodo
2020-10-20g32mIn0VHK4AKLRtD.exeexe 5a0da4c740eec17778ba4ae16cd61e7937185ee6edc1ddcff0004a252ee01733Virustotal results 17.14%Heodo
2020-10-209CCO6JoY.exeexe 8e57be467c4032d9d748dca897526bdd44db50880b2958edbd044812d97d6d87n/aHeodo
2020-10-19PhsxA.exeexe 2e09adad4365dd19b78d64540ed0f3f2abd21ad379f1cbb34b91596b625234b0n/a Heodo
2020-10-19TePKAo3df5BUGasEyV1.exeexe c1c434f1e791f9c97ff26660a80c2d690fc35de642b5defb377f7596062d9721n/a Heodo