URLhaus Database

You are currently viewing the URLhaus database entry for https://autofit.pt/wp-content/jjVLAR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734034
URL: https://autofit.pt/wp-content/jjVLAR/
URL Status:Offline
Host: autofit.pt
Date added:2020-10-22 10:32:15 UTC
Last online:2020-10-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 10:34:14 UTC to abuse{at}keyweb[dot]de)
Takedown time:2 days, 0 hours, 13 minutes Poor (down since 2020-10-24 10:48:03 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23HWW4UUNVA.exeexe 9faebfc221b266f0e88b74878e7e0fd60e5089fde2213a52cb752d09a52d86a1Virustotal results 23.19%Heodo
2020-10-223Fp.exeexe d78a18f708296a05203649ef315a822df0685b2a5539ed906e3285408bfdd04cn/a Heodo
2020-10-22yXj.exeexe 4b788d244b4f579d9f664384983c7273b6dfbec6de46b2dc337784a6e28e25dfn/a Heodo
2020-10-22bYk.exeexe 57ce2e78551ea5c5b59a3d3271fdfd13c225e18610b9194550bff03ccf0f2c6fn/a Heodo
2020-10-229D1eB6kitcqO.exeexe 1d55e2dba28c27dec531d049a9d876ea930c0bd02be6637833e1a625ed37cfden/a Heodo
2020-10-226.exeexe 8826cb451015080605957524895a58f777c027f5a6c32d3990d64e958a7ab9bfn/a Heodo
2020-10-22MH7asbdRIqftip1.exeexe 735d362609ea73f06dfe32c2f11ff52e6b5a5b9f1fb42b10c293c2b064830cb5Virustotal results 48.57% Heodo
2020-10-220KxMiiTw5.exeexe 91fd43d5e9d02ab33f4e9d4821a28e649e31b199056e89e4035f2da76f6d3d08n/a Heodo
2020-10-22ARWaCYV92i.exeexe 213c4716a3fab49a8345430408028175c629a713f578c9c78733252a7d5b00d6Virustotal results 50.00% Heodo
2020-10-22SvFapDloa4XwgV.exeexe 04714b064471777ca574a990408439bba9933928b75d8ed3d639b26ee9860017n/a Heodo
2020-10-22RW2Bk0u.exeexe dbf14537514f59f90e3b5eb9f8cd0e5ccd1b2bf59faad2c1bfbe679072ede42cn/a Heodo
2020-10-22JalQek6vRvRgmTyZVn.exeexe d1ab527900abc303d9b11dd585b03c603b83c1b05992b900ecc943d98f7e5582n/a Heodo
2020-10-22wDBTXhEZAqPxbZx.exeexe a63d55d25bc9ed8d0be5ae42646b8b06e0f7f3282e3ba4037fd084d83a38febdn/a Heodo
2020-10-22C2fe5OphXm0jwTdlhQKW.exeexe abb6aa08d5afe757b43b194ab1e8cc2be48be0471d9e2297dd2fd4d68b41c995Virustotal results 49.28% Heodo
2020-10-22AcFEd5zVSPXDWAD.exeexe 6551af6d8dc5a2813b2908fe74bfab70d066443a47bbcfc52b85fe5c71546a64n/a Heodo
2020-10-22Bg5tEjsgpC5.exeexe abe1a15b22a760e7671e10e31c84b1980c17d5ed682cc8b52a20bc5e81f24e66n/a Heodo
2020-10-22Sl.exeexe d78f666287f4684dd573d1bc598378d4e09036959000659ca840ef40911ad5e6Virustotal results 46.38% Heodo
2020-10-22bnmkQxf6fMIs8VL.exeexe 1a482d5d894fc274dbd95ca182dd04607e3200563b7015f9c58eb1ecebf67345n/a Heodo
2020-10-22iYoOTdRQrjeao.exeexe be4cfef6ee41c9437dedadd794772ae38369708394303190daa58d7847beba5en/a Heodo
2020-10-224DKnR8x1sW.exeexe 48621b894170b58ce828de3a1777a157435181402b8e00266c932a455984bb23n/a Heodo
2020-10-22Pq0Ieb3mEJgS7z.exeexe 268f5d0f1618544a6caa793fc01ddbee65ee9d207887765c855d9483adc0ce5en/a Heodo
2020-10-22S.exeexe 90af81afc1b3e5120cc8a0fa22f60aaf75d9feb8870913f5b0936387307e4d5bn/a Heodo
2020-10-22NIvuucq8n6.exeexe 39bac2e092c19323fcb95686199bf9177697dbf88026af8de7d5b9da4b127f43n/a Heodo
2020-10-22jAjnmivCLznv.exeexe 50fd3354da3cd178bbf2754b709f163add5fe8c8801c9102eaa6022a2d0d298dn/a Heodo
2020-10-22S1E6B4v.exeexe c7d29e94a56e75cf26833e6274992007e8022b371c0ffca972b8694c85aaf7adVirustotal results 31.25% Heodo
2020-10-224dxx7zso.exeexe 94585a23f2175109574deaf67cc4f1f37a1b5e93cb38db010a586f087aacd946n/a Heodo
2020-10-22NENtQJuC9fmc4aRR6.exeexe f161230733962e585f3189de61785fb7b617e37d0d13c9a23e2867e508183bc9Virustotal results 26.47% Heodo
2020-10-22M4TttJ0HSW5Azw.exeexe 1307c09de1b88bcabedec0a4283828904178271015a3085e66ed57f31094a37cn/a Heodo
2020-10-22XNjOX1sOdrnrLAHY.exeexe 88784c200fe77ddf78e29a1dd7a2ad42e21f20bd79d4a57d8449c34ef9ddf48bn/a Heodo
2020-10-22dXtBsXuGXYU6M93a2OOj.exeexe 645a15a43305b3a0d6526cb236a526f3dfaa7038d37c968cee15cecaa1613fe8n/a Heodo
2020-10-22qmmDZ35TEGwXIV.exeexe 5373bd17808019460b23ca97efc810166cafe076ebe5f7810ee8cfcde9115c51n/a Heodo
2020-10-220pOO8F4A.exeexe c0c1105b725ef60d370df2c2416690f522ccf554d45c56b64fdbd716c4bc7361n/a Heodo