URLhaus Database

You are currently viewing the URLhaus database entry for https://australaqua.com/wp-content/xIt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:770455
URL: https://australaqua.com/wp-content/xIt/
URL Status:Offline
Host: australaqua.com
Date added:2020-10-30 18:48:05 UTC
Last online:2020-10-30 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 18:50:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 26 minutes Good (down since 2020-10-30 20:16:09 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30UlQuVRH.exeexe 0a6fd7839a85b25c658705c3074b28ed5dd5a1a956fd06d4ae5d7d5631ea01edn/aHeodo
2020-10-30G3BWoqqQ9l.exeexe 198a640ea30ce6c337e416e1814eb6eb9518bcc4e0385677094333c7c9cee467n/aHeodo
2020-10-30EjKmaCFk.exeexe aa65fb14bb3165150205dfbc7aa9b03eac7644b6d6a0aef2d4dab5d26fa0e933n/aHeodo
2020-10-30S9yt7BhLq4.exeexe ce6baf7949e4b73f9ca39bbec543ff3733559bf8c454a94655726ca46a1f5063n/aHeodo