URLhaus Database

You are currently viewing the URLhaus database entry for http://dirads.com/wp-content/Bro/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726013
URL: http://dirads.com/wp-content/Bro/
URL Status:Offline
Host: dirads.com
Date added:2020-10-20 23:13:16 UTC
Last online:2020-10-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 23:14:16 UTC to abuse{at}liquidweb[dot]com)
Takedown time:6 days, 19 hours, 2 minutes Bad (down since 2020-10-27 18:17:11 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21qlImFXrmB.exeexe 932db792981b37d32dc1d51ea496497bb00a0f216c0f7d9f6b0c97a63aa79cd8n/a Heodo
2020-10-21UDCcAusrNo78.exeexe dad13a8139c639321930666a07ad71ac3b4f55469c0ccd838c47c1d02438a550n/a Heodo
2020-10-21gTGFdZCCh.exeexe 5e1689cabebbe89b19cee8551e8076fec43116d2ffb7a427aac5c6f1137247f9n/a Heodo
2020-10-21CtnqSfUeUtTy7R.exeexe 0756c7409511e4d23b82724ff26234bb70ec04b8e0a83dc2a357eb1a84db654eVirustotal results 19.72% Heodo
2020-10-21mYY.exeexe 3a68210278725ed9ef0354e07be3bba2d9eda226c8075e4c4e09e37e9a4e0cf2n/a Heodo
2020-10-21psVR3dyDI4PDCuS1.exeexe 28a94d60f776d185ff30343e5259b4c54ad4431d250929c686ce62b259649e93Virustotal results 17.46% Heodo
2020-10-21K.exeexe fb0c6aba4a8afc7a04e37461ff5ba790d79e6066ff74b3e88fdb7fc11a5c2758n/a Heodo
2020-10-21zXCWHAyGdSmB3LUred6y.exeexe bb60c489b78b037c8a6b23f300658443cfc94d234c89a2605339edcd335a47b6Virustotal results 29.58% Heodo
2020-10-21yhIz0LIEPw1cJeB.exeexe 4ebbc26f1991dcee6ef2fe01ee9a06f2b547cf0c9c96023a1c5a54a894966ac3n/a Heodo
2020-10-21f83Fflrlm6D.exeexe 29de9e7b0cd9ba2ebff0f4fde0d0a56b95270fb33cfad0bba53a86a55ec491c8n/a Heodo
2020-10-21Flro.exeexe 50bf1a4fe5dd0a4f7f4da46f156441eb4deb1af248174d340714bb06473ee17an/a Heodo
2020-10-21l9ORXa0g2xyRnliEzT.exeexe 174f53eedb3461276250c55774ff1daf1aa2171f386fc3e6260a6606d8af8cb9n/a Heodo
2020-10-21l9ORXa0g2xyRnliEzT.exeexe 174f53eedb3461276250c55774ff1daf1aa2171f386fc3e6260a6606d8af8cb9n/a Heodo
2020-10-21GK.exeexe 3d4138a674cd7cd0022c7e25ada3b1ebb039d89c10ccf9562f64bab37685c4fbn/a Heodo
2020-10-21V9j8L7J7xRk7HlF8dp9o.exeexe 52972e2d81e3127d7901cba1da90459fe5bd0030aa2d650dc589b539354aab5dn/a Heodo
2020-10-214E9Bmp7V2wyLZiMW3S.exeexe b80c0ca6dd543ebb96f90e4f0d96bd653e720d7f2c9c17dad5de1dcb9f3837acVirustotal results 22.54% Heodo
2020-10-210tDx.exeexe a3b9bcb5d29a59c41a8fcdb6b45e30ccdf7eeaa7a347447fbc2a794b300aabfeVirustotal results 19.35% Heodo
2020-10-21LsMVQbbpm99.exeexe 71a93fc70d1bca24b01dbf9e7ebd990740c08d5085241f26e5479a1630a30bb4n/a Heodo
2020-10-21IFW8lHv7IKx.exeexe 7b8d823c641303544d6317c7c60003e8ec3431fc3872581a23231d29dde85365Virustotal results 15.49% Heodo
2020-10-219fozx3tXPR9kr8mxW.exeexe 0242c8f4030ec81ecfec7989f184897f63d2ceafd885ff41d4693ca75cc7e1aan/a Heodo
2020-10-21ScseQ4z47nUiqe6MwBK1.exeexe 6cea83fa79efa6c10f524180bab7c27cd865f7e27b7acef7122b9ca5372e398aVirustotal results 14.29% Heodo
2020-10-21bWuIFe5YgxJ9C302ngN.exeexe d879cee5fc9fe7e683f8c259fe763f9f1df305b3959b677007a2a06a603a552bn/a Heodo
2020-10-21bQwZqtn8AoJxc5m5z5.exeexe d9fb16af5facc97e9547cae71876b7086a47e652f7ba9328d465f51665905611Virustotal results 14.49% Heodo
2020-10-21JH.exeexe 28d09658485d0606ab6a59561b8adc183db974e8106dc7ad2f451035b18f49e1n/a Heodo
2020-10-21d8xqTNXI3mgd.exeexe 471e6cb20a44a018a0e884b03939af3e1cc5e072e6f8e1f1c5cfd392168f1d92n/a Heodo
2020-10-21iyYGrzq2R4e.exeexe 67a66b0b79e9d07acb2a113fcb86a5c5eaa5fa1970d3cc8831bc6f49843c053an/a Heodo
2020-10-21PPP7l4o6q7G98UnAP.exeexe de6b509564f32ed7761bd0c54f32471358d18c0330fa587c8a6116637bc29887Virustotal results 12.31% Heodo
2020-10-215aRO2BWLwR.exeexe 753edbd1ec56eecdaa349cb499e9821101a638a480cfdd1a0edcb41bf1f55f7bn/a Heodo
2020-10-21him.exeexe f50fd61390cea264740fd19ef01003df4dac09efae54be5861464df341fb5dd6Virustotal results 14.52% Heodo
2020-10-218bF6ws0NG.exeexe 5c6e17b7273a7deba420f6f8744e707a4c4973f8b51d499338822f5fe6c23795n/aHeodo
2020-10-20Rqvb9TM2nu0vSuHYG.exeexe 6caaf5d300440eb57dfa2f50a3cc1a85bb1e60eaf7e627c52a2e2b4a55620f36Virustotal results 14.08% Heodo
2020-10-20vLel.exeexe 581a8971273c7cd58f786283f08ed6e78541c6de76d627655661febc38f0dbdfn/a Heodo