URLhaus Database

You are currently viewing the URLhaus database entry for https://quicktowtowing.com/wp-content/mu-plugins/uMM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756533
URL: https://quicktowtowing.com/wp-content/mu-plugins/uMM/
URL Status:Offline
Host: quicktowtowing.com
Date added:2020-10-27 13:40:06 UTC
Last online:2020-11-09 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 13:42:04 UTC to abuse{at}digitalocean[dot]com)
Takedown time:12 days, 22 hours, 27 minutes Bad (down since 2020-11-09 12:09:42 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29SFJVeB04ptd5Qiz.exeexe 3c14e86debedf5a247374cd4baf5628f3d577478a10020f14c42d4721f9742a5n/aHeodo
2020-10-29SaVUCOm1t.exeexe 7e0c71f53590e6286340bb5f7ede2e19d5efe74fb76294c5057595c3dfcf2a93n/a Heodo
2020-10-299XxbCMDtzZ93.exeexe 6ea9b9c2189d74da5a9fc28efe82956f2fed98420c4734259b1ce8a5a358b420n/aHeodo
2020-10-29ho5pal2gnffP.exeexe ad27c8e950196e9426b4dbed17b5c63dd8287f496fd53225d25f96b65c77d343n/aHeodo
2020-10-29Tg8LjDuc0UpZktqSCYYF.exeexe 9487b55ad32d8351489387583bf9b2f8ff761dc5ca36c13613283543cd07c0b7n/a Heodo
2020-10-29UhYwI.exeexe 8c4047fbbabb58880337dda69679d60b05db17c4d2e5495218b7b3b5e000797an/aHeodo
2020-10-272qdXRpbgL00Jjk1yP.exeexe c1b93ced1b6f70e7bcd4ddbf20d7e2e68890afe75e1b6190d9740851b9168083Virustotal results 17.39%Heodo
2020-10-277T4pplSchMt.exeexe d72013673e30549cdf842924e7cd4bbc369ca9e643ce1443449fb55cef4722aan/a Heodo
2020-10-27KdhAW.exeexe 7cb397028c091a0473a8e2733c728587572c48ced41875b152d30136ca09f6f4n/a Heodo
2020-10-27FU1NJWMS8kudabKBTwjiD.exeexe bb0c62ca0db0b0b3d67b7662098dae92d7703176d0c7258a512b0c11c2c00949n/a Heodo
2020-10-27wf6WA4O1wks90if.exeexe b374ffbb05b17c7cb0744c577e20050564b9079f7af1b0c49e7ff814a71ee7aan/a Heodo
2020-10-27pexE.exeexe d333ff8ff182a29158a384f77227a682a5cd02002ce4b2ecb9ba0af9b5400a80n/a Heodo
2020-10-27ZcG.exeexe 9e8471b96d9cd309383e511873b368ea4935f8fa6f88c452a98da2f76b646817n/a Heodo
2020-10-27c4CFxbLSAD8vPGG.exeexe f885716d560c3f67862e84130e6fdce81bef0468c638a95d23fe6aec4d258844n/a Heodo
2020-10-276gVLRFZhTpQ8ToEH2G8.exeexe 54ca61558b79ec0f971d097498190cc6ee2dcb15fab400e1f43a658144102ab6n/a Heodo