URLhaus Database

You are currently viewing the URLhaus database entry for https://blog.6b47.com/Assets/w5U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761545
URL: https://blog.6b47.com/Assets/w5U/
URL Status:Offline
Host: blog.6b47.com
Date added:2020-10-28 16:15:09 UTC
Last online:2020-10-28 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 16:16:21 UTC to lir{at}linznet[dot]at)
Takedown time:2 hours, 43 minutes Good (down since 2020-10-28 19:00:08 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28L3WpPqSX1reF1MD.exeexe b4a134d82aa9c9ef0dcd243dc01773607f2fd21e1894584b59e80a221ae8fe0eVirustotal results 22.54% Heodo
2020-10-284K8u1Ib.exeexe 6e7958457560c5ef199e8d92fa132463830d162aacdb60389b361088051c3388n/aHeodo
2020-10-28FM4c.exeexe 756db37074bf87b54803c7793c07bd0976c3969505935c0870eb386057556687Virustotal results 21.43% Heodo
2020-10-28c5weqBxp9RSTrJWe.exeexe 1fedcc8359e46b0d9d127f76cf86f125a99f23bcf0313f6c371d1f0c18c1e6a9n/a Heodo
2020-10-28KtxTNG5lXh.exeexe 05acd562d174f923101afe0f88c628551448b13ce9121f5ad5148cdd6f665664n/aHeodo
2020-10-28BzesU9qmYjn0.exeexe a2371410593e02dbdfa16723454634ea2b09c2e452feb7d2f089fa4eb9a3d180n/a Heodo
2020-10-28ZUlvNNleCTiUPVsO.exeexe 4054bdc6d452fbeae15c90cad7a7de1a8bc6a87c3f45e33fedeecce29a42ac9an/aHeodo
2020-10-2888AfG3IwQpjNmTFep.exeexe 0bc8f6bc7b2648119d97d5f4ea8f59c5b825856a9ac0fa8837b6d2ec08cf0354n/a Heodo