URLhaus Database

You are currently viewing the URLhaus database entry for https://cs.vitalero.com/wp-includes/Vf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:736451
URL: https://cs.vitalero.com/wp-includes/Vf/
URL Status:Offline
Host: cs.vitalero.com
Date added:2020-10-22 20:38:04 UTC
Last online:2020-10-23 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 20:46:04 UTC to abuse{at}wedos[dot]com)
Takedown time:6 hours, 59 minutes Good (down since 2020-10-23 03:45:27 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23iRC4.exeexe e920289a74791ae6552b3ab9f41708631edde86d57038755356e6c0181c76effn/a Heodo
2020-10-23FToJVInim.exeexe 58d19e7273f71991da2e3f919d57aeb1f3448991eddae6eb17dad9d60d87e11cn/a Heodo
2020-10-23clbJtcZo3KJUU961av.exeexe 1402beee417de55081640cb26446e42301aaf9ad007b05d330080724b82ff28en/a Heodo
2020-10-23ZDntdBDVX0V.exeexe 7c7dcbee1ffb8eb58d7f3b59312bac77b5a762af7a146320dbaca78a154f5056n/a Heodo
2020-10-23QpvMlBhoor.exeexe 4e9010cb22252e555eae23cf69df92fe9a0d2498ec83499f371783632a045f4dn/a Heodo
2020-10-23fM9JAA6sNdR.exeexe e638132eb09d9785e58873433309c3e3097ac07aea50257bc4ced3c491ff2a4en/a Heodo
2020-10-23E1wU.exeexe cffd9ca2ee6e14ec1485415786e576b0334f1cf9d794be3cf8f3563a6786c676n/a Heodo
2020-10-23ju7VNXXeeC6JfrSGtQb.exeexe 8527ce9c37b11928a6704eac33526fb0483f5354515bf1ef55bbfbfde10e4ac4n/a Heodo
2020-10-22tdfzbsQZKYuH.exeexe 654ef6bdaba23190b0ba735f94a1b2676cf45c44be2c5c241f979ec723dc7b99n/a Heodo
2020-10-22U5VtqF.exeexe 03020144d1912d6f7f0ef2dbc66f7af1f0c140093cabe1900115b55de78c202en/a Heodo
2020-10-22BqXPy5gov.exeexe 12153f1a4eac7d56968e5984f04a2310d6c6198e1a96601335bcd1904f277ceen/a Heodo
2020-10-22oJ1X3g.exeexe e5e8915162e91eaf064d8acc8c323ee4af0e6ab5b59a171a09ea71fee6c7a98dn/aHeodo
2020-10-22zlDGFsf.exeexe f5490c083eb99fb1544dc32e1ea639d71638103daf0c1a384d02d3db3b3cd55dn/a Heodo
2020-10-22ne8ZDVaAOdq.exeexe 6b8325f12067ad68561495db3faf0e71973df0c88973be67e44fc6fde22edacan/a Heodo