URLhaus Database

You are currently viewing the URLhaus database entry for https://mohamedsayed.com/wp-admin/Zt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:722425
URL: https://mohamedsayed.com/wp-admin/Zt/
URL Status:Offline
Host: mohamedsayed.com
Date added:2020-10-20 08:26:13 UTC
Last online:2020-10-20 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 08:28:20 UTC to abuse{at}nl[dot]leaseweb[dot]com)
Takedown time:3 hours, 18 minutes Good (down since 2020-10-20 11:47:14 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-207nAq080U0ARYYLMnm.exeexe 28c2700de3713bb5d399ce826d89b480e9dd715231b9d7885664a111a89c5afan/aHeodo
2020-10-20wTiPkrzxXGui5kOmm.exeexe 065fcccb6677f952e96f78dc27ae3f4e061d39ac4f42232c7fe9066635c8f3fbn/aHeodo
2020-10-20dGON20w3Z0m336QmEh3Tj.exeexe 14e728001151ba2754be427d96f294c21362235a81b908ad069992e9e07d5621n/aHeodo
2020-10-20WzT765zl0uHOb.exeexe 7082283827c897b392bb9bbee0ac6f51f39431c7d0944b21b31e75b43797f1cfVirustotal results 13.04%Heodo
2020-10-20g1AfpNAYa7M0peI5u3Vs.exeexe e9e8e285d21d6d84d23ff1e1b17cfb5502252f6b12e6c36c17eafddfc08a1fb4n/aHeodo
2020-10-202sCF2REJEZCb.exeexe 4e216622c02f805b93eac78df3efe09bf2c7716f9e390a858bdbb25d3f344ea3n/aHeodo
2020-10-20Evqx.exeexe 6dd499eb2ecbe7e696b0432fe1ef6693b6df0ad65d11cec0b632f5c351f4a6fcn/aHeodo
2020-10-20xeu3lAED9.exeexe 9d5720308f36dcc3309dd57c4cce06f3f8b979111432ca0e3dce7b905f200ebbn/a Heodo