URLhaus Database

You are currently viewing the URLhaus database entry for https://fitthemes.com/wordpress-5.3.2/O/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752743
URL: https://fitthemes.com/wordpress-5.3.2/O/
URL Status:Offline
Host: fitthemes.com
Date added:2020-10-26 17:51:06 UTC
Last online:2020-11-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 17:52:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:8 days, 2 hours, 4 minutes Bad (down since 2020-11-03 19:56:50 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30viYwqu4mR.exeexe fed449bea63223816f35b60a0c5629994ca3866db9ef00013356fbc0db1188edn/a Heodo
2020-10-26QXeOms966RS5l.exeexe b0ef88c160c3f31118c7c0342d7d7678a4e8b5d874aca717308aa79813c89e62Virustotal results 11.29% Heodo
2020-10-26mCN5mGOEr8oFRcNTWm6R.exeexe 1035944a789298c971681c0a3b5ef83149d8fd09e356d3475a2305ab99e6de77n/a Heodo
2020-10-26ODXT9.exeexe 2b5564a55ecc7a6ca1095a3e1a7c4ddc7542a3358b2b273e3243715e0c56269bn/a Heodo
2020-10-26njV.exeexe fcdcb0c7a308c3c65487ff8024598742d1b06a89050cff473c3e2ecd787f9a41Virustotal results 11.29% Heodo
2020-10-269VInhTRuq.exeexe 22926145bbc508ebad90bac0ece16e6eb91471409393edecd7fd2dc4a38c3fe5Virustotal results 10.29% Heodo
2020-10-26YfAIMss7Mu4qURNxwW8.exeexe 65a3a72ba68194478bae70bb3659540db2622d92a34d9a0284b0b6a7933c8365n/a Heodo
2020-10-26DJ5Mn.exeexe 06a1c23ae83d8bce047e5051c6fe2c45f81f0e91ecf227daa4fef60a6ce218e7n/a Heodo