URLhaus Database

You are currently viewing the URLhaus database entry for https://ngllogistics.africa/adminer/W3mkB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:769581
URL: https://ngllogistics.africa/adminer/W3mkB/
URL Status:Offline
Host: ngllogistics.africa
Date added:2020-10-30 13:58:04 UTC
Last online:2020-10-30 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 14:00:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 hours, 44 minutes Good (down since 2020-10-30 16:45:08 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30GyGO3k5.exeexe 8bc27eca4f728fbd207ac77f732671670f1528c0ddd582110469e7270580b881n/aHeodo
2020-10-30LK.exeexe 0fa89e7a77e217de0a93b02293edb4cd4070275c8b139cabdd0d846ad5b0be3aVirustotal results 23.61% Heodo
2020-10-303DbpGsFUQ5zwWd8R.exeexe dea631467e11ed4388cc9b75334d2afc09fdff9d1d7800615486c8a61ab5af29n/aHeodo
2020-10-30TGMjNx10I8SM4sh.exeexe d566a589a93ddba77915a5ada272eec7d9495dc65871ec36e3eb47e2853bd27dn/aHeodo
2020-10-300zK.exeexe 6a53a8b4b03fa80c2af796db6afe9ecff3461a6d87c07aa440167de31e4ea078n/aHeodo