URLhaus Database

You are currently viewing the URLhaus database entry for https://nhatcuong.xyz/wp-content/Szx94QD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752749
URL: https://nhatcuong.xyz/wp-content/Szx94QD/
URL Status:Offline
Host: nhatcuong.xyz
Date added:2020-10-26 17:51:10 UTC
Last online:2020-10-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 17:52:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 29 minutes Good (down since 2020-10-26 20:21:52 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26q4f2PukDBp8oCN3.exeexe 4bee4960989682523426cb7bfa389518370ccc51095164cf410fe265eef4c2f1n/a Heodo
2020-10-26mVZ2MbwxRMqAYhOhp.exeexe 209e5d61901dcef7e693f1bbbf4a0ccf2aed282dd41d03acbf67420fe00b8b65n/a Heodo
2020-10-261Snxdonzb.exeexe 54b286923a9675550a9941fed418b0ab2dddefc148fee6b1e6ab1344145ac2c3n/a Heodo
2020-10-26olIm8yPNqc.exeexe b4faf6fecc6114d59116f6d634270ba47eb1bee4143ba921705b88f65c90c609n/a Heodo
2020-10-26tLnDw.exeexe b7e2318502c6d0b4c5759480e639a3a4c8726acdcc30a6199f7f467fadeef113n/a Heodo
2020-10-263b8R1THnySJh8Aq.exeexe 7c387eb30ee8e37cc80f8fe655cae67a392ea069ae938e06b7274c886ee0f1dan/a Heodo
2020-10-26wUCmk.exeexe 0f4d8160c7889958a6f191858f07dadd4220aaa4b6e5733f18e4044a31f075d7n/a Heodo