URLhaus Database

You are currently viewing the URLhaus database entry for https://kriya.co.za/cgi-bin/GgSkXPb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:721627
URL: https://kriya.co.za/cgi-bin/GgSkXPb/
URL Status:Offline
Host: kriya.co.za
Date added:2020-10-20 04:47:13 UTC
Last online:2020-10-20 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 04:48:05 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 hours, 45 minutes Good (down since 2020-10-20 07:34:02 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20k2.exeexe 30d1d3265a91a06771060a28147a68389bf55baaba58735528fb3dbfa7256f30Virustotal results 19.05%Heodo
2020-10-20dzjmo.exeexe 248f2403a3e73728663b4264922cdef1adf5d2d585ec39d7488e7c81682f375fVirustotal results 18.46%Heodo
2020-10-20EufwjlIMZbOTE.exeexe 7c7331198e83afdbc51a0eb165be9ad3b560469698525f7dcded807a9a38b13an/aHeodo
2020-10-20K2fROcvbFt5GUuQez1Je.exeexe 7f1f39d51f79bc782424abc3567c075a6df0d84d9b4c57bb8ec2668b9ab38f35n/a Heodo
2020-10-203yAk8cRO2F5nLj.exeexe d47b03c72c72d460fbb39a03b3c7a8e5da4820b60863757d2d340e681bef8e73n/aHeodo
2020-10-20SFF9JYxuL3gPCXEa.exeexe b5cb4112c9423ad6fd85719ee99f857e94c0e7ee405fcde7f52997c793ab7fddn/a Heodo
2020-10-207Y5IMHmdCWDF0J6HkLZ.exeexe 3adc6c62554974a010dafcd26ce231bb96b47f1941b8004de933276742b65ff8n/aHeodo