URLhaus Database

You are currently viewing the URLhaus database entry for https://needhelp.gr/wp-includes/Qlpz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751710
URL: https://needhelp.gr/wp-includes/Qlpz/
URL Status:Offline
Host: needhelp.gr
Date added:2020-10-26 13:17:04 UTC
Last online:2020-10-26 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 13:18:10 UTC to abuse{at}lancom[dot]gr)
Takedown time:9 hours, 16 minutes Good (down since 2020-10-26 22:34:51 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26XSg3j9tsbeB1mZ8KAQ.exeexe 60f10d5cf1433938410a6fcd3539fc06287c942c3227dbef0c266ac323deb093Virustotal results 15.49% Heodo
2020-10-2630q2.exeexe b873278e698168b9fedc3586d5e97bea69978d139ab378e2b6cf489e12f78818n/a Heodo
2020-10-26cCkh8ywXJ.exeexe e7cc56bcfe0fd548e6024120275c767926056552eb342ff088e6424fccb83e64n/a Heodo
2020-10-26IAQ2ZcNnoz9.exeexe c392bb97cef718d781f09a01d0c188d581b9e0b3be8feeaf3e2ee670ac45d1dan/a Heodo
2020-10-26xxL.exeexe 3d3a9d50804492b6b3584a8246a890f55a16661974573b2eba11201c3832cd1fVirustotal results 10.61% Heodo
2020-10-26jr0185Q3Z1icSSanRAc.exeexe 3539d7fbfc06cd2b3b8df8d812285ca7aa1144d5887e84937c5eb65a61c0fb0dn/a Heodo
2020-10-26ZHIFDhXvUjT0Q.exeexe cc27788877cc3687ed02827f5ae44a62330c33fbf0a2ec709f1deb94cbf52ac7n/a Heodo
2020-10-26OeAaUCd5UjBDMhE.exeexe 6d0428ae1f7b417fdbea101bf4c77618cf24707edcf95860e4a77cec38651a40n/a Heodo
2020-10-26P0tw0tWEdt0Wkx.exeexe ffaea1675150a57a6bc7f0226a7defda57240b71ecb81caf64a822cb4780a8b3Virustotal results 9.68% Heodo
2020-10-26dWtGBYk2q.exeexe 6dcdf86d4a0705baea777e54875283e2800cf557627b05cf36f4086033e449dfVirustotal results 11.94% Heodo
2020-10-26Q5J0CcgE3g.exeexe 712c48c2e9f5be468dd297dec336ac3c1aa534badf28eb2c8e223d5a89e29c9dVirustotal results 11.43% Heodo
2020-10-268wUV.exeexe 2f8b67ab2da3c91e6fc23db64c521d54a164c3fe6e222e3d6d7da1db782fc975Virustotal results 11.48% Heodo
2020-10-26o6r.exeexe c5361318498fc998ca010e0f912802402f8e6d79742cae13c19f85b31c6d6614n/a Heodo
2020-10-26k4r0ftMOVbm3YzHUdunD.exeexe 55ad93578544e70234d0f4a87db65f710a0a1162982032cf595fa87e78fb7de7n/aHeodo
2020-10-26RQb.exeexe 63e86d7fd54c04cb7baca6b31d4f73790f1903c5b007f457847f1a508d54017bVirustotal results 8.20% Heodo
2020-10-26gbMZ19NVe5H.exeexe 59dc10e5f61cb4280a19c5ece892d6bb620ea610e7fb9f10130ff09bf5916455n/a Heodo
2020-10-26TwgdId6A.exeexe ea85a6c527fc7174b1b953e6d5b2a617e79703ad1fa1db9f4ba131e0a477a544Virustotal results 8.20%Heodo
2020-10-26C0yWhzYc5GyhsLf.exeexe e6c451cf9021a04dd56ca5f13fbe4369116cca5f3fa14ce964e3539ed7d3ca38n/a Heodo
2020-10-26tSjxYG8d.exeexe 93ce2c03c37f5abb377734619b0580eee49bab41487ade7a473a34df11553de3n/a Heodo
2020-10-26Pxrj1.exeexe de7a47203f1d0735b03e79bd56e498aefffcb991bc7856ab90540edd243b4ea4n/a Heodo
2020-10-26Ma6p2XGwumFDtfS.exeexe 6a6439924468ae7447d9f6f41a88906f7ce5e02bb8ab7f2eb1738de96b379a29n/a Heodo
2020-10-262tgSBvQPReRDZIkg.exeexe 24a560c114510228b98616ca7c7970057dc48cfc96e5d2f67f02164fed51321cn/a Heodo
2020-10-26F62BowAeOHaWkJ.exeexe d6360bd76e5af74f201842101ce587faee3e8f5cdf0dd646271fe60071c7641dn/a Heodo
2020-10-26C5.exeexe 5074e7da61dec1a84469c5ee7e3442c7b3ffbecb2da89b6f07e2619ea6528c76n/a Heodo
2020-10-26q1we5h.exeexe fc420d20dca887c17f30b5591699ebbc1e0dd17a93c18b6acebea1528378c5f3n/a Heodo
2020-10-26YTO5yNVIRspP.exeexe d105c9028792ec4bae347bbc3486aa04f254fc75f10d74cb06c0870addf28f26n/a Heodo
2020-10-2692jxN1pu1f0MAb.exeexe 31bcf413d19d9dedc4bb5ba61c771fd0966951db5a4a0024ff7f2b22100566e0n/a Heodo