URLhaus Database

You are currently viewing the URLhaus database entry for http://rovonize.com/email.rovonize.com.rovonize.com/M/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724281
URL: http://rovonize.com/email.rovonize.com.rovonize.com/M/
URL Status:Offline
Host: rovonize.com
Date added:2020-10-20 15:44:05 UTC
Last online:2020-10-20 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 15:44:09 UTC to abuse{at}godaddy[dot]com)
Takedown time:5 hours, 56 minutes Good (down since 2020-10-20 21:40:19 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20RGBO2cUHhGr.exeexe 14516c84636c0a08a65bbf41749ab19e78939a036ac11e47f59b63a4b7b89080Virustotal results 12.90%Heodo
2020-10-20PGKRsKEHfbUGSfcqk.exeexe 2b1ade6c232d723fceae61d0e61e7a4fc71a856f2e2f438c495699c3b109406fn/a Heodo
2020-10-20hB7xVtZIRuP85F1U06hA.exeexe 4b3b742e1948cf866d5a60d740197b8ba235789384ddd3c07bc55a45e475f1b7Virustotal results 11.59%Heodo
2020-10-20JSLj5GZZmOu.exeexe 0f023433bc5fabd1f8b2220e7e0bd2041c6739891e61580570b60e636b9a83d0Virustotal results 19.35%Heodo
2020-10-20IMkvx9xvgwg20e.exeexe 28fc144f6a52c10e47a5b1e5c83c3767238b41877e1e854e0e81a836cc110bdcn/aHeodo
2020-10-20YSTMZADdB6s.exeexe 50d2680db0cf44f316c270575177645c858c5c65fae41549036613b2b06262cfVirustotal results 19.05% Heodo
2020-10-20NnqWsDy3L.exeexe 52816d26da5a8690b45d3ac8a5a608964d45f6b5ef3152ac5ec43c10471a0060Virustotal results 18.57% Heodo
2020-10-20hdiHK.exeexe d53d863d4590da09fc70b195119bf3429b2ccbfb7cc204836aba6e8bfe0f732en/aHeodo
2020-10-20v1c9o.exeexe dc5df7260ea296c2ed65f26eee27faa5d24387fa2ca3c9f94adbcb39fb7c59afVirustotal results 18.31%Heodo
2020-10-20fdaTYs.exeexe 0013b4ab33703b8b82aa0dc5f7a480ce9f5410c5486ba3a5187bd68138a735fcVirustotal results 19.05%Heodo
2020-10-2050SnXgPC8VVubJC.exeexe 87a319a472021ea53e23bfd15d7dfc31795dcf5eed1cb2d377d09f50666cdad9n/aHeodo
2020-10-20VWUG9ik.exeexe 14b6b794339280ee99caa7b98ab6bfd73154a4e50609b7b1df3cad460287ed59n/a Heodo
2020-10-208sNgYxfnSKu1j.exeexe 22eec4748394357d599fac32b753334915cb740b934e3d8b6477d30ca2519466n/aHeodo
2020-10-20D7zZ6gp8M0.exeexe a42678520c12766591ca1cc91cb1bb3db08c695177db4352b18f6cdb439bf4cdVirustotal results 17.39%Heodo
2020-10-20e5Xsbr.exeexe ccc1c09c8d787f9cca15c998b666ee044d6f033f97383ac26009bc00591ac721Virustotal results 17.14%Heodo