URLhaus Database

You are currently viewing the URLhaus database entry for https://natfast.com/wp-content/geeVh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765955
URL: https://natfast.com/wp-content/geeVh/
URL Status:Offline
Host: natfast.com
Date added:2020-10-29 16:25:08 UTC
Last online:2020-10-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 16:26:19 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 36 minutes Good (down since 2020-10-30 12:03:01 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30XFKOP.exeexe a5d7ccfb32cdfb67000c95465ec7676b85307fa9d534dca75121d0be0e139f24n/aHeodo
2020-10-302VEySh0E7eOpsr.exeexe 34eac099acd8cead8103f35e1446913d602ff7ee2b12aabd691cec3d760a95bdn/a Heodo
2020-10-30ElWcdLF3tDAZCZ5NUs7.exeexe 888741f6a2fdd29176aba41b144e8a711f34ef69100d17ef84845b2e3edbc0f0n/aHeodo
2020-10-30o6xCmZTcGBw.exeexe 77de76a6a5f054a3b27fb9b81b5d91fea03cac89c210e0364ca77417c71ef936Virustotal results 12.50% Heodo
2020-10-30ZQcyPS.exeexe 72db1361bc043edd2a9f7e1900a969738b7f010634dff21d97094ed0db4bf6d6n/a Heodo
2020-10-30R9O6o6ttm5zxY.exeexe ba5902f8b84aafa17ad57cfd8546863f3e1ef0f1a436fd6bb3121cfe4f090e75n/aHeodo
2020-10-30EMsnXdm.exeexe 0907ba734a79b45a14b7c3e962679fa5781b346f24a02e9c206081778093e4abVirustotal results 44.44%Heodo
2020-10-30C571JWXYsAvqnKXDhs.exeexe e549925022ea09f5ffc0a804c6d85dfd18a5ae8fd58dd5e8f15225de5073ad86Virustotal results 42.86% Heodo
2020-10-30FESyeacDLAH.exeexe 361232fb555da6211f0a7473a4ca3b6ba6c690a9d2a8c4dfd72c622183653d7an/a Heodo
2020-10-30vCk7Y.exeexe dfe07c5987c001dbfc0ab9540b40df8324b62ca8caca48d9d19ac718eef369afn/a Heodo
2020-10-30dsuK.exeexe 0b666f6b4adc8723ebf740970bd52823090efaaffd96fbf108d430c21726beebn/a Heodo
2020-10-30Ja55ehpF7baZM.exeexe 33fafe05cc0eb79364608e68562c3a1533c7b4f5b66ba2e572ee33c745662edan/a Heodo
2020-10-30cHifgJOERlHezyt.exeexe 104a9fee14121ecf0745a946eadbc423e75c0306d55269088021cd619b87a1c2n/a Heodo
2020-10-30Rmne4J92SA963uoCKr.exeexe 9dee52a302a61aeef25fc3bbc407014622296f5cb549f824257bae8a631b339an/a Heodo
2020-10-30i51CI.exeexe 3b3fa17bb819753f96405165411fd49e876518d6ae6ecd25b293b9120ca16c4eVirustotal results 44.44% Heodo
2020-10-30YpRWE.exeexe b9b46610c9a3cc308999fdc230b9244a6edd2fed641fac4f4c63ed533c19b41an/aHeodo
2020-10-30gfBviFqQ.exeexe eb5082475338a95e590f450ebcd2da75d6648a69a29dc4ef5f9e29a67242b1d2n/aHeodo
2020-10-30xTSsme14jh3q.exeexe 7c280bafd0f96ae9a329b2ef7fb2c6a5782d9028dfca8da7a57b68e1ebf2ba09n/a Heodo
2020-10-30PffaZAFBGX.exeexe 1e46b435213807e624747773887faa2b400b104a0acc564718648c08b59cce0aVirustotal results 40.28% Heodo
2020-10-30pAwo0NawYv.exeexe c7fce6ea4b171145015493d81b9de62ae5a87981f09ed093af2e3f4a2417e322n/a Heodo
2020-10-30U4cvhBBx3VFe.exeexe 6204fa6521ca72bfa660b868064382993289eda72d193ca609e1899274a9bd85n/aHeodo
2020-10-30gXLwayW90OoX.exeexe 52257fe57789fda5c483354556a0d9342ff422cfc78092cead175a5e78c2f75dVirustotal results 31.94% Heodo
2020-10-3057v.exeexe 91b5d6cbc865f955e405d736ffc80b2ef8358e99f80ef5da559b7389f4517de8n/aHeodo
2020-10-30IJv9.exeexe 9e6f0aeafe227efee9628ff28ff123cf4a81a6f525f26b1ec722cffaed39666fn/a Heodo
2020-10-30CnxFkEF.exeexe 70b9b2046951178a7388cb1604e495a7e22001ab2f43843e85d0d8f2629afa2en/a Heodo
2020-10-30fmE5wVM8NIJsu66AB.exeexe dec3ba78c07d0af4be805429022edca71751127985c014d69262ee8220de49bdVirustotal results 25.00%Heodo
2020-10-30iAVp7f47bKXDc.exeexe d19cb2f2556af9104afc1b50623e3902d057af2cd58afdd8f9db5e341834ec96n/aHeodo
2020-10-30hlfv8ABaE4RZr08mEQ.exeexe 062bec4f4e7aca9b24b97042708c9165fde79653c17e14711e99886f5783ae6dn/aHeodo
2020-10-29lEwQeaODwUc.exeexe d06ffbcfc05fc158b3d6d1ad422d59af6bbdb74956dcb3b50d23d35fd3fe722bn/aHeodo
2020-10-29s.exeexe da6ecdf45892f9bef6d92af958564278d56c28fe60d79f3393643edfd19c52f7n/aHeodo
2020-10-29UZN6RO1.exeexe b70bd8fd84233cc79b5dd3b142c7597e4fdb25648bab345012502577ebb74675n/aHeodo
2020-10-29Oge6nLVRnASx.exeexe 46a8b1199a06d213536b6f8f454d3379deb22d5e86c5368a898ba85180d00915Virustotal results 22.22% Heodo
2020-10-294WtsgcKp4F6M.exeexe 1247588addb43fbc95c39b5aeb05046f521545115a5fb7c137f099b7be570de9Virustotal results 22.22% Heodo
2020-10-298u1QZgQqPnQnR6g.exeexe 7024166f1eb3fdc635bfadffec03f671dbde0b91d8077bfb69c16141b2f2f903n/a Heodo
2020-10-29ZbYNUVjXN.exeexe 353559990d648d7615446285d98e9c0168b667bca2edc947ba693a3f2decd9ean/a Heodo
2020-10-29ZOsyaAhnb.exeexe b86736f2224c104f52dc80c491dbca5fbe7cec771ad5bb79081056eae483370eVirustotal results 19.72%Heodo
2020-10-29HS9kH5EYN39hWAWJv7.exeexe e0584807efad555276479599763ac39df46efc2efadcbf0d1925b828e18e34ebVirustotal results 21.13%Heodo
2020-10-29DssRjhpd2Kru.exeexe c61700a004db7442ffb2e6ef3e410a46dde5250e48d832118e131d5f29e5a746n/a Heodo
2020-10-29VoG.exeexe eef526e3e8741697f5d23743e146db670d40dcb36d4f62ad04f2eaf68980df5cn/a Heodo
2020-10-2954WXWN4VDN4UTe8aE.exeexe b91b9668eed95c3b86a5db9aa1ed38330b64d6b109647820585815517b22e4a7Virustotal results 22.22%Heodo
2020-10-297Ncvedv.exeexe 20ec91fba8d98065b3fbea68c2fa7c4b70e686db095da531edf90d599a3f0130Virustotal results 22.22%Heodo
2020-10-29hV.exeexe b91c7d51aa13c1ea88aef8e590e2945ed960f5f6240bd782379cc3a3efa701a8n/aHeodo
2020-10-29qrx.exeexe 894d45ab9c54a594d9f256d5f83ec1753990dbc58f672d9166de9c8823ac31f2Virustotal results 20.83%Heodo
2020-10-2959DBDKIh.exeexe d07841404275c0372222ef50ba31f375420cb69cc0315e4cdfde86327144477cn/aHeodo
2020-10-29mEziOR.exeexe a363eec9b68c7195df966f690d898006bd69d2dce50344981449d7b6cd8f2719Virustotal results 22.54%Heodo
2020-10-29fGvMn.exeexe 2a99445ba407d14ceeaad733bd9ecda68e5ec7b43a2fa2febe7c2003e0d00f10n/a Heodo
2020-10-29PBseEbJTHOlmhnHD.exeexe 117ce99bbc3ceace9e94ea36b197daa8829a2aa2633abe7cc22119f5e5de3c42n/a Heodo