URLhaus Database

You are currently viewing the URLhaus database entry for https://ayur-herbal.com/wp-content/HIw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762661
URL: https://ayur-herbal.com/wp-content/HIw/
URL Status:Offline
Host: ayur-herbal.com
Date added:2020-10-28 22:08:04 UTC
Last online:2020-11-05 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 22:10:08 UTC to abuse{at}godaddy[dot]com)
Takedown time:7 days, 15 hours, 45 minutes Bad (down since 2020-11-05 13:55:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-297Pom0.exeexe 05e0c7498af2996ff880056d3b2d922a9e3e46811a3bc93e59015d1d12a2d7c2Virustotal results 17.65% Heodo
2020-10-29qecaqnuxq.exeexe fb7f5cf1bdbeb7f9d6da853bb7f570b2c08cdd0cd2814c39a2890ea54542e439n/a Heodo
2020-10-29OLt2uTTyFe.exeexe 93c2f3379bae24205ee83007fb4570af91a96a38d4e33697b2ff4dad62b1d9e2n/a Heodo
2020-10-29SnRvGIyQa.exeexe 3955a077193dae3ec336fcee549eeee5629c0dcfc7c54be04fc1321545ef719bVirustotal results 15.71%Heodo
2020-10-29ID79EW2kPKF.exeexe cf25c6d9adde080586242c91b3574ca69aa315cd465088fa36c36bca4926eea3n/a Heodo
2020-10-291wUOKLNs2LIy.exeexe fdee0de600ce25a912d3be81a95567a97ace309b49fe234e66f0f2ea57e62c52n/aHeodo
2020-10-29bGZtzL.exeexe 20e9cc4188ac36def0df25fa01429971356b096a032d38f83d2a3b60f53f41f7n/a Heodo
2020-10-29gVnib.exeexe e6c46459972531191d77f551a6335bcf48282d97cdf710542247bbfabd156adan/aHeodo
2020-10-29yXlbgRgBP.exeexe 47ad97a3f4c9022c7910a85c9fb3837c932feecca6e3b602623ad7caf8ad22e1n/a Heodo
2020-10-29IDbcD5A6A.exeexe 83dc54144b561f45b59d6f3305a583eb3cb7792c28c5d44c842eaee3ee040efaVirustotal results 15.49% Heodo
2020-10-29UJ8qlL3PV44UkjS1bo7LJ.exeexe 37f827329573453af3a9c6c0fce87d8c384ef484b7643b2b420542a6ae9b112en/a Heodo
2020-10-29aCemb6RJ0A5FFnaB5s81.exeexe da9c84d57c6f5cdc4cf85b6cd2d201fb8093735aeab27f5b49c6432ccb2f472fn/aHeodo
2020-10-29gmGKnbh6GpaV3lK.exeexe 769b17facefa78ba526ab35ec76ff3af76985bab3507cc9a92d5794f24598fd3n/a Heodo
2020-10-29VwClhbekSZq2l7g.exeexe 77648464b901254df2488ef02878a3cd1aa3cb4983a13543af6e3f26dd00a952Virustotal results 16.90%Heodo
2020-10-29m9be.exeexe 86bd8ed4f07c850a7d380ae50d37f57a6be10a8a7ad54d3ee5149d7bde64e62cn/a Heodo
2020-10-29SfxfVtgMbyUp.exeexe 488eb13fc2e35c286721ec24198d7aec0dc0d51a5a6a2e46679e0936241aeef2Virustotal results 35.21% Heodo
2020-10-29r4elvWuNUD1OVdCs2t2.exeexe 0eb110da6fedabfe771fd0752282ecb2e6237c062935544e41a8c24e06055647n/a Heodo
2020-10-29XYzUGfi7p.exeexe 901ab10ec0c50800a0222a3bbb8df3aa7f534241d08ad47ca6720a7a1b36d974Virustotal results 36.62%Heodo
2020-10-29fpgOwHECcoOObi9.exeexe fa207acbe6de911a575b7f7ba3c72cf52bfb05fc89f335d616f24c49b9bc4c45n/aHeodo
2020-10-29wSC.exeexe 0751e62816d8d6d93701600a81bb0c9d05dafa47c0ebd4f7093e0ea677bcf929n/aHeodo
2020-10-29xDn0.exeexe dcf6c1b2857a81f2287dca73f4013b3a6e5fc47cb41a3dafa41a76dd70a5ec28Virustotal results 26.76%Heodo
2020-10-29dLogWuTyY.exeexe da30dced46b599fa3fe34aa40e6feafb01958f4581396332e394b60dde63cb96Virustotal results 22.54% Heodo
2020-10-293tPCp4wS.exeexe 145b8f9672610bc04abf0b48976d16a4cb3b423c693c6bfc6fd144375bba6c1cVirustotal results 21.13%Heodo
2020-10-29TYZau3vQvXI9ZB.exeexe 494c543c215433828bb506b2c895cd7c6d7052546f17ac75603ccbef2f532434n/aHeodo
2020-10-29DbvlZHqFguIQ9V.exeexe b2991e97adf93a9916a7b20ee522a978cb20881ac65710fc9dc05aa5b536d1d7n/a Heodo
2020-10-29uh42wkDBee.exeexe 1048b213b6902456ff40c74c529c7597e3164e6c8e72f6a3e5d5ff0d1b02a8b1Virustotal results 22.54% Heodo
2020-10-28xL8y0lOMp.exeexe 732070bdbd8bdf572da3e32371dad4d1b5fb1313178e57430dad858933b11d6en/a Heodo
2020-10-28PfNqRYgwP.exeexe 3fbf8828dc963ec425ede4003f5faa49fa2c17b535b0d0eddfaa5dc6b7efa5dbn/a Heodo
2020-10-28SIZVo1JHbrGHJjKYs.exeexe 7e8bfd1421cb3bd84bbde104b2ff6c58d74c2a5526226bf6c5973d9356c1300en/aHeodo
2020-10-28Ba0gwgoW.exeexe 57fdecddc55fd49efb0dacd455539ea62911871511ce22a695bf22c027006430n/a Heodo
2020-10-28kiQYmOs2tSKqofdO2Z.exeexe ef725b160912d7138573210778d5d0d5da73d56d7e5d36387c7126b2c0883f98n/aHeodo