URLhaus Database

You are currently viewing the URLhaus database entry for https://timsonntag.com/cgi-bin/g/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756517
URL: https://timsonntag.com/cgi-bin/g/
URL Status:Offline
Host: timsonntag.com
Date added:2020-10-27 13:39:08 UTC
Last online:2020-10-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 13:40:16 UTC to abuse{at}strato[dot]de)
Takedown time:3 hours, 20 minutes Good (down since 2020-10-27 17:00:20 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27LiFqPKAtyRKrGg8NPVIs.exeexe 1387d8f1b3b4ff27eec54de2a66fdbd4725651733053b5f6ecd1af8bdf82a423n/a Heodo
2020-10-277gwmO8.exeexe c1b93ced1b6f70e7bcd4ddbf20d7e2e68890afe75e1b6190d9740851b9168083Virustotal results 17.39%Heodo
2020-10-27Nea.exeexe 7b522b76b11080ae863b6f06aa8c46e8ffccccb687be89677b23e35d65a1bfa5Virustotal results 22.58% Heodo
2020-10-27ZmmixxbBl3DW5hB6LhiK.exeexe e4c73292d0d32fd7fb20f17669461527cf03c275806b2cce98513cf60bc6de2cn/a Heodo
2020-10-27BlZRQkE7nGC8.exeexe 8e2e2174fe1920517a7a4d2b60f0a3faa99004989e9d3350daeedb6212babb87n/a Heodo
2020-10-278PFoDJvm.exeexe 380a953f85e460428e07f682476d23eb717028f90cba25d9b03cbf70a4642986n/a Heodo
2020-10-277rou7IxHl9Y128GB.exeexe de6bcc456ab20809310adbc8b52ff0585c7bcd22a24e1bb14fbfbc37d1c172cfn/a Heodo
2020-10-27g5s.exeexe a989d26a53c627764096626f3407b8b20dd96fb3b37ea7af04155debb5d6f4a2n/a Heodo
2020-10-27fs9QGgh4JYU4o4ZVxfCT.exeexe cd2535d46fd05f06586920d7151f567ea61814f036885a9eab1f5d795b91d5fdn/a Heodo
2020-10-27sG6FcdfUzmwHrL.exeexe e5c35b5f9467191fcb8698b3a7c08c269f1a9fc037db233c5cfd45f646c57329n/a Heodo