URLhaus Database

You are currently viewing the URLhaus database entry for https://prodominiospruebas.tk/presta/u3U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:721626
URL: https://prodominiospruebas.tk/presta/u3U/
URL Status:Offline
Host: prodominiospruebas.tk
Date added:2020-10-20 04:47:12 UTC
Last online:2020-10-20 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 04:48:09 UTC to abuse{at}softlayer[dot]com)
Takedown time:7 hours, 42 minutes Good (down since 2020-10-20 12:30:57 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20RENMNlV.exeexe 0950c1c3d529dab37051abba25150ef64240c7be603cffdd9a6d45666a1b9920n/aHeodo
2020-10-202B8Qv1y1kgw.exeexe 4c33a32f7b5596edc2243455053730bc8edbe09408abd568233bedb30670742cVirustotal results 14.29%Heodo
2020-10-206e.exeexe a7a642e2d42f253428f9f5be94732822c77ec38f0428a6ef3e6a6a4bf1d3f94dn/aHeodo
2020-10-20HCvSo8J9gfDltCQKrV.exeexe d314e0d34029e21dfe8c905206207b3fef6e5259e7574cdbc4165a4064ef3aaaVirustotal results 12.68%Heodo
2020-10-20m3LvB3zAD.exeexe 4164758ff89164824651e418520c0b5ae237e9c26eec13071a4daadb4fb340cdVirustotal results 12.68%Heodo
2020-10-20Zl5U0BHtnjJWd.exeexe 225f391b82990cb9d31abcff53490bb6ed8b894a3a6cbe270aab3c9594bb2912n/aHeodo
2020-10-202xthB4Z5D6G.exeexe 14b6dea37c010febb29919a8534c4a8b274ecddde9b10dff0dca10dbb37ae214Virustotal results 11.43%Heodo
2020-10-20645lMQC5ZNaK3rMPgC5.exeexe b49604c260dce20a680aa5e8122c268f7320c50fb104dab03470244aee078bb3Virustotal results 12.90%Heodo
2020-10-20fACncOMFOAud8aUzy0EK.exeexe 42cd9f0a4a1b81331b458fb22df06124810e4f1d610de99f577ca92afe69dde0n/a Heodo
2020-10-20BTNuYG1I.exeexe 8c1fab5716ee708b742591f53f185a29941271d79b03f9e53e432bf5380335a6n/aHeodo
2020-10-20IWds.exeexe 26726c2f070f1581de5d9ce2b6039b1a996ac828f3083a103516bdf2958783ebVirustotal results 16.90%Heodo
2020-10-20SKwOHTPaF2Gu5h.exeexe 5b201fe37c607c089e2221073055eeb05474a9d28fbc1ef4298c6c985ca0f4dcVirustotal results 16.13% Heodo
2020-10-20DoGGnXSnABJ.exeexe 40aeae6c3f474cba2315f06aeb3bd2ed0b7ece5e16a7cc49a406b624823581a5n/aHeodo
2020-10-203v04MrGguqIMld.exeexe 21ff9aceb38a04cf1be9eb7d4993696ec15f0717396b2c9795a673d08ae61084n/a Heodo
2020-10-208BqZtQ3XF94BtcwM4z.exeexe 6f8d9dc02269f999d2a0e078694aa8483ecd4c8804d3087d600e74191e58be5cn/aHeodo
2020-10-20l7.exeexe d674c54f45bd1dc7e745788a05e8dc4d1fd2c0223bb0e7bf497166a1c5070059n/aHeodo
2020-10-20w.exeexe e24d074cf83d9c92c4f727ee7bd72433762f21fb6e8d2715001cc673a821ea30n/a Heodo
2020-10-20NW7FZz.exeexe a88dbebbe3c2de49632db093b01c26ed45b686338cbc725553dca5a5c30557e7n/aHeodo