URLhaus Database

You are currently viewing the URLhaus database entry for http://twogirlscleaning.com/openbayl/KaI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729566
URL: http://twogirlscleaning.com/openbayl/KaI/
URL Status:Offline
Host: twogirlscleaning.com
Date added:2020-10-21 14:07:17 UTC
Last online:2020-10-21 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 14:08:26 UTC to abuse{at}linode[dot]com)
Takedown time:7 hours, 21 minutes Good (down since 2020-10-21 21:30:09 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21UA9yyYdfCHL.exeexe 0677cb5a6f56a82009384138f05171135158d441b07b10009cd50621dc397a61Virustotal results 18.03% Heodo
2020-10-21YIR.exeexe f7db9c0acbe793fb730673528dd60cf01e528cc599cfcc2ba129eb0e40e08933n/a Heodo
2020-10-21eOSjVMtsz3t.exeexe b868fa34852d29b43ed665a936c2f9e4cac7de5720edd34f0485e4c4d21136aeVirustotal results 19.12% Heodo
2020-10-21T8g1IM9yk9UKNllO.exeexe d7a51b820e8ec38d04ca5f99f536086e330d566d3e84bbf4ee346b604dedadbdn/a Heodo
2020-10-21DxUKSeeFcwIYlfFV0wNj.exeexe 7c52c5c304efff6ff5a079334682d2483a634acb9ca75799643edfe67231886bn/a Heodo
2020-10-21JJcwP3LSqHiq.exeexe 814c913c2259c6aa282851bad4c3ef23e01d95f8fbb1cbd41e0816e9e7e0d22en/a Heodo
2020-10-2140aD6z.exeexe 00843ed494e8148a67ec8ac97f2d98144b701a025156719afbca32ce1c394d55n/a Heodo
2020-10-21KaMxgorZ7I6Kf.exeexe 3762394e5ffefc1d408b6dec7a46accde3f5b2f8d15bd62873f9b5fd03757035Virustotal results 11.59% Heodo
2020-10-21fVYs.exeexe 8108561c5abc24af14a93288422d36acbd9cfd30c8cf063bc8ab522147b045f0n/a Heodo