URLhaus Database

You are currently viewing the URLhaus database entry for https://420extracts.ca/cgi-bin/Ecv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765278
URL: https://420extracts.ca/cgi-bin/Ecv/
URL Status:Offline
Host: 420extracts.ca
Date added:2020-10-29 13:15:16 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29SWWQ5wRsbmc7yW13Eba.exeexe f97759276b062fad76fec2bd2ec75f6d73083a420b9057fd29bad76f0b715feaVirustotal results 16.90%Heodo
2020-10-296QCvzs27Y1GpsqAFe.exeexe e80e91e35901646fa537e9dbbdf1c99244155bdc91031b04c461238bbd898787n/a Heodo
2020-10-29EmL0y2PX3d.exeexe 09f5d04a0a6bca12ef7406dc157f90d858a14f09f9603dd2bd2fae90ce31dd5cn/a Heodo
2020-10-29yMC1OLqZZwIAfSu.exeexe c59b382f67f1f9af568c25d5497a144d5d0f286666dbfc2d3f310ea57a158425n/aHeodo
2020-10-29RpcWL.exeexe fb8639a6e0c87c89f4c88dd205a5697b0281f1c1e765b3eca17c054adc8b18abn/a Heodo
2020-10-29HYvNmTNcdwR6.exeexe 9ba0186727c85482ff42b6167b9012b755241abc9b6821f5abcdf475b9714b13n/aHeodo
2020-10-29JRL1Etj.exeexe 5b0688cc96ee4265a1297b4294399a7c5bd71cdb679848ffe16aa7351f0282e5n/aHeodo
2020-10-29r8ulP0Z2AWLwVRn.exeexe 90e3651e3198dfc2879c5a52a2bbe8b2f51b9421d0e14d4ef1964ff1fe64580en/aHeodo