URLhaus Database

You are currently viewing the URLhaus database entry for https://uvibrands.com/QIG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:736459
URL: https://uvibrands.com/QIG/
URL Status:Offline
Host: uvibrands.com
Date added:2020-10-22 20:40:09 UTC
Last online:2020-10-23 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 20:42:07 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 51 minutes Good (down since 2020-10-23 00:33:36 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23CwFW8f0l952bn.exeexe d3e983af30e9e48dd650933b6f2431f4b3dcd5bc7bfa089c363fad920f1b4ea9Virustotal results 18.46% Heodo
2020-10-22bVN7.exeexe 857ceb3d53a04bbb6f5aafcdbf5a9f06eb2d1ef8b949b23ba452a50547eb961bn/a Heodo
2020-10-22FAUq9adB4VrqHsVV9.exeexe e844aef43e6b948af4512a4d7d23901409676120e3df98aef0315a2022f615cdn/a Heodo
2020-10-22PHLq7a.exeexe 29c23aa23e15d583e20d928b64d4fa5507f9dc730e0d5f8a9c82371688bd7470n/a Heodo
2020-10-2220TKMNbtu3HGA44Yss7Rp.exeexe 63a94d3116d5aa72ab18789dc8df29db6a2bde75d257f2d4aeeccaf0884e76d3Virustotal results 22.06%Heodo
2020-10-22thqlAy1OJIU8rDRWC.exeexe 6ddfe680a77812384ca1a492ed34908ef05b9da52e5d8959929a567ff54c0472Virustotal results 49.23% Heodo
2020-10-22ufQC.exeexe 3d1cc975358fa0a302a89c24ab804aaa49556414a647c1f05c5b97c0b9546d15n/a Heodo
2020-10-22zQuqREBthD.exeexe de5e71b2fe5b6f1f6e7f975e694560ebe4621a553a0065614796c01f59363362n/a Heodo