URLhaus Database

You are currently viewing the URLhaus database entry for https://kvvdedu.org/wp-includes/MeYsTO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724282
URL: https://kvvdedu.org/wp-includes/MeYsTO/
URL Status:Offline
Host: kvvdedu.org
Date added:2020-10-20 15:44:06 UTC
Last online:2020-10-20 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 15:44:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:3 hours, 3 minutes Good (down since 2020-10-20 18:48:03 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20AoVdCv.exeexe b5fcc5b21bce93693975894cbd8b235cafdca7f9731063bc34e04a4ff27c3fccn/a Heodo
2020-10-204jfb215P1Q0ZRqc30V8V.exeexe a494c87a5cd9bbdcdbbd33eff1cd3085982a5a347c7d3b23bbba8f96ed55cbbeVirustotal results 20.00%Heodo
2020-10-20tVfql.exeexe 2c6e028264a52d27b9c94e2d9f6bee2006308c185ee373f7ea7f1b6031310ebdVirustotal results 18.57%Heodo
2020-10-20u5F5D5dpNLy2oUuZORTe.exeexe 439dcacef75529851a8cf0e5c28efe7c28e9cc9bef8729e7a0410e30792ccd53Virustotal results 17.65%Heodo
2020-10-20Y6V4JvQTD05.exeexe 722ce81172c621502ade44bf23ac824167f9c591cef46b3c4cd6142b4c7357e3n/aHeodo
2020-10-20qNZWenv5rHiB7Olh.exeexe f3bb2156183eda2a4b90cb44f088919de25642334a222752f118377522721b44Virustotal results 16.39%Heodo
2020-10-20G.exeexe 73d9c3b60a34dc56c183c18ae32508e3819a7bc1c6b66772cedafb1ed4707ff4n/aHeodo
2020-10-20TAogG.exeexe ef2a5c12e76ad7cd6c8e607a579af338ea572d8637304a4e630319feb84388dcn/aHeodo