URLhaus Database

You are currently viewing the URLhaus database entry for https://universallearndirect.com/wp-includes/9VCAoTS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726397
URL: https://universallearndirect.com/wp-includes/9VCAoTS/
URL Status:Offline
Host: universallearndirect.com
Date added:2020-10-21 00:58:14 UTC
Last online:2020-10-28 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 01:00:18 UTC to abuse{at}liquidweb[dot]com)
Takedown time:7 days, 20 hours, 22 minutes Bad (down since 2020-10-28 21:22:40 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21Y8iQbzEUMRffaOgB2.exeexe 78f0e4bcf05633f25c5c55707773fc6911ae560bb36439e71854811e97f621d4Virustotal results 20.97% Heodo
2020-10-21JTQYHYFU.exeexe ef076381c145ccad7fa91c1f1e2d16a1f62daa043c70f230087ca4baaf1470cdn/a Heodo
2020-10-21QS.exeexe 347641f98e597a2f44cc767f440e695ce9ddd43cfae9fdf0f410cf5ca58838ccn/a Heodo
2020-10-21cxWxZnw1J.exeexe 4d6bbc46106158a3e8d3e1bed344277fe4b30ddad0a2a45d3b9acbef51a18f18n/a Heodo
2020-10-21zT.exeexe 98ebc33736c4ba62dc0b79f1d46969304905863800367bba4d0409f5475802fdn/a Heodo
2020-10-21TIhJaSto88pS834RoUW.exeexe ef01ded9bce45b76c1086ec8d837f73d1f9bf4fd490c37a855cc7481b22a96f9n/a Heodo
2020-10-21kuKvquYbsh.exeexe 7ff7612d69263abed8b6662b138e5654bc3385acbe3050be9927cc31500fcf1an/a Heodo
2020-10-21OAo3WkTO.exeexe 835f972d1ccdadbf15d58fce6ae7d471841b1a816efc498c8d60c714e4f45d54n/aHeodo
2020-10-212RmzwVtPSlb.exeexe aa1d0ed7939560774e93b2373cc1f795e3755b074e6e94687c71416a589fba52n/a Heodo
2020-10-21hqgLOWaRRvY07.exeexe 46553ba94ca748e05fbdf4b927178c4d36581836ac846e2cc8476d02a2e911e2n/a Heodo
2020-10-21fHPuJdHbGG7.exeexe dad31cd4864dbede004afc0b73cdcf8ba497cb21bacf911e53b8c03d54e73bcbn/a Heodo
2020-10-21PNGLKKA52OqvCkui7KPx.exeexe f08ab5bc58a95fa561571fb40d9a090f5abef4165a9343ae72b7be9cbac3dfban/a Heodo
2020-10-21a6tz9oDeb.exeexe 0a4fccfec78c1742023129b8c3e3f82373a90b277efe0dd0e6d385577fd3d47fn/a Heodo
2020-10-21xg3V.exeexe c05bae67315094b566741c5524b41bf97556edfcaafc9b125f4ad2d2b13bdcfcn/a Heodo
2020-10-21VAMBDAoWLEDac.exeexe 7bb82bd6496371098a9991bd487e4fe5026b96f6a7e6ada4490b52f9735d661an/a Heodo
2020-10-21rBQ6wB.exeexe afecb35d7a619f9480cda2bf477215f8105fcc59dc4cf932751a11c900f3afdfn/a Heodo
2020-10-21tJH1PHwuu66weOLJb.exeexe 16830cca2d2f32ba814e1646df6c3cef03e64760ec50384084f1578d2e8f83can/a Heodo
2020-10-21BoK5NfcMZnYhuiYh8T.exeexe 2a7e3641a54a0f647d8a1adb8c6373933f0c6edf09c944709682ab6bf113428cn/a Heodo
2020-10-21x.exeexe f2b1c66e693379331ae26c94b4edee41cea93455fc82fa6835a4c3bba8e80af9n/a Heodo
2020-10-217tVDhf.exeexe dbef44cc8cf984fe52a83b0e57d4a4f8e6d21fa6e4e20ab0f43939b0c1ca0872n/a Heodo
2020-10-21Yhx20l.exeexe 44cce2064546798f1689d6f5c1296b521d34a38dfed2f8b6970d242932be19ban/a Heodo
2020-10-21lh.exeexe c8c0355515441d06ed8ffdfacece145f68903c131b229d1ce3ad5e391d857062n/a Heodo
2020-10-213Iy3p17aKdpz3.exeexe 1d13d1474c2f220284eaeb7c32d7167da16af3ce1e4d7353a210ded82cefddc6n/a Heodo
2020-10-21Xs8clL9mE.exeexe 5f9260ec6c4998264a149199a04046715bcbcf2193919f62bd14811cc600542bn/a Heodo
2020-10-211VyyMuXmagvcIx1MCh.exeexe 5da6dc89903a23904e6e5ae0f546efc90c71b0cd52fb2cf30958a8f7c8407dedn/a Heodo
2020-10-21BLVNOY.exeexe 7076898d5b8b184212880c76053d39cabd695096e1a186f7d9ee6acf191c7f44n/a Heodo
2020-10-21pkAZjVjEiwo.exeexe 17c712efbfbb4d71f5dc0dbb114a24f32c697db09289be75fca7f6f5a3491868n/a Heodo
2020-10-21WBO6dgOCeBF.exeexe f6433df80bfd43bea37228b89709f06967b4ca3bfa3f565c5051366c51b62bb6n/a Heodo
2020-10-21KSfTtPYGIIwzFs9ryAd.exeexe b62866104a1b3b8698c679b5037f4ff2a47777ad7083c10b0e6c45ecf7f19198n/a Heodo