URLhaus Database

You are currently viewing the URLhaus database entry for https://sangbadjamin.com/move/r/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726017
URL: https://sangbadjamin.com/move/r/
URL Status:Offline
Host: sangbadjamin.com
Date added:2020-10-20 23:13:16 UTC
Last online:2020-12-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 23:14:15 UTC to abuse{at}hivelocity[dot]net)
Takedown time:1 month, 14 days, 19 hours, 59 minutes Bad (down since 2020-12-04 19:13:45 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21vYl0.exeexe 24956b6123612a89f434143923c0f9deb2aa1621ba107aaf94969a42295d50edVirustotal results 8.57% Heodo
2020-10-21YF6kcDRktmdqrSpQR.exeexe e371cb27fb2fcb73d8f57d72ca0c19dfa7f93d2d1a556ff398768a9cc12f19b4n/a Heodo
2020-10-21Hs.exeexe 562fd7f4077ddebae5a934f3bd400eba3ddab11619c3e677b87dcbc423cac2a2Virustotal results 8.82% Heodo
2020-10-21rbPUHFaqxU.exeexe 1479d97b7dc1816d93fcc6da95991581174e5e9f86271fe933dca9dec1fcd199n/a Heodo
2020-10-219Vkps.exeexe 9ec5b2c483deb7b154a8f1b8a474621df494710708ccbc56506109356743613dn/a Heodo
2020-10-21kBMsDu7NkqSIhkPqKn.exeexe cef93a32278f252e6686224d0673804b623a74d408c3785d062c804147e12095n/a Heodo
2020-10-21Z00c23.exeexe ebae1a9402843c52ea98b357a66983221010690424cfb1ae96ee19ee92f1905cVirustotal results 21.74% Heodo
2020-10-21EQW3UDEx.exeexe 4aa305938bd3c39191525448aa352477d9b4862f5c23ebacf8bef00cab88c540n/a Heodo
2020-10-21jqg6NZ4KVrmf.exeexe ae2f4804bbde87bea8483ab2e5165b0ede005891ccc4b629953633ba650cc783n/a Heodo
2020-10-21dXFvblCuj.exeexe 090f70602a314265769b7c87d2ec26b2ef78dad74a2dd6374cb9bb0f043556c6n/a Heodo
2020-10-21ZxQ88uV9f1quissQu.exeexe 2cb5fd4da3e09872e273b40cf4b5407775d59491eb27b6dac0f00ba0621041c4n/a Heodo
2020-10-21Kg8K1T.exeexe 92635bf2fc51d4fbebf2a113596b2fe20b2858e37671d4eaa5f4d843fb317d1cn/a Heodo
2020-10-213JsILrpYB.exeexe 920c8dd7132501a277ae1e9419a5339bd53dccb0988a6208f6beb01e51ead8c1n/a Heodo
2020-10-21MiG9e19hno8.exeexe 11636f50167dcd55fdd30eda9e6ab68a0298c3fd3b16a0c46a104e9b23e04c14n/a Heodo
2020-10-21GTf9D3JA5kd.exeexe 90308b88271f92a6f35fc56ac1a0915d5492231e1645ed5f8c8c46827cc709a3Virustotal results 24.19% Heodo
2020-10-21JoTn.exeexe 7fa964e77c3395672abf792122da12bdd57274a8fc48a894a9495fcc222649e2Virustotal results 23.94% Heodo
2020-10-2187McdAkdOQUhGYu6WZ.exeexe 31d0a2f9326dfc322aef1afc9bb508e2123470249ab2893d76cfe54cbb847ff1n/a Heodo
2020-10-21McPSUW.exeexe dec94a836241f460f670419c91f5aa44c0df7035fcd584a39d0e6f54612dff7bn/a Heodo
2020-10-214oepwy8e7FijStZO0Dt.exeexe 305b7f51e2fcaacfd888793f77a60a854c65aa0c9bf14252caf7c9b49761e7e0n/a Heodo
2020-10-21aJS6h7XikNfyb.exeexe 6e8b45ee271659cb1ab2b83242072e6a31c0131b15ccdb3502fa1990a3adf4e9n/a Heodo
2020-10-21zz.exeexe ca4f427d7514a7d7e3e6c7bc21cde9a52afecc004a95f0b2c88e34733288ea09Virustotal results 19.05% Heodo
2020-10-21fdbxA5kX5nPr.exeexe 94be81e5bf7c6b1b5097df5376e687aaf235f774920191636eb0eb15903e2530n/a Heodo
2020-10-21H.exeexe bbc7faffb0d5e68ed6b0592fdf461e9af0f102ccbf6624c1ce81ce5be3ec8896Virustotal results 17.74% Heodo
2020-10-21T.exeexe 909a64f966e5a03511e2a95c63ebfe29619fb58af29a44f8010287f74f3ea0d3n/a Heodo
2020-10-21R.exeexe 4b7417ae3a4a47c40d1545b7b9c0050bde858e0ef3d3de143536cfa6b6c93239Virustotal results 14.29% Heodo
2020-10-21eVJ4aaJ.exeexe 86b78051cdee9ecdb889baf5b6b121fb26d03d6e651197a8664f2a8fd6f9e208n/a Heodo
2020-10-211So.exeexe b1cb5c3a437327d850bf4d1f6129bd8c243879d085ad3425334dcc395e7ef79fn/a Heodo
2020-10-21AC9.exeexe 3a205ce640b25b7d264f0198721c200b897b41579373ce3fc4cc8f228fd634feVirustotal results 15.49% Heodo
2020-10-21MCzGLnWR5T6HrZddcRe.exeexe 8acff1f33fe86f2a7c2c5cd73636439e8fb00c98dfa16e9d9a1e7adf1e21f9cdn/a Heodo
2020-10-21Bus68F5xuszKGQbvqEvj.exeexe 9e39908c1d4624d07358b9a369751fcae3be4b6beb260c52cd3adb130b16eab3Virustotal results 11.76% Heodo
2020-10-21yjbWq4ppk7KGE.exeexe b30dcd976a0ec96735e99e9733e40ba41606f066918bae6c8e969a0f2b638d4cn/a Heodo
2020-10-21Rn3A.exeexe a6014de792bd1cb92daa59df0dc83d9b2e9937d99fe3bb4bc1e5871b94a24197n/a Heodo
2020-10-21iPs4b2I.exeexe edc5e9279b952bc4e3586731301e0d883f1c142129f13e86a7f426fc52cf2b25Virustotal results 16.13% Heodo
2020-10-20SrPUPBOeb.exeexe 20f7fe6f8afcc61d5dc62f164193bc7263af7842bea7eb3ad3544b9ec52cf2c2n/a Heodo
2020-10-20HAEQkt0HWSOM0FIar.exeexe be4dfe741f04b075ea4ae3c99e91ecb57b86b98b457f4f6be3dafb68cb2e912fn/a Heodo