URLhaus Database

You are currently viewing the URLhaus database entry for http://secretariaextension.unt.edu.ar/wp-content/bK which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:77711
URL: http://secretariaextension.unt.edu.ar/wp-content/bK
URL Status:Offline
Host: secretariaextension.unt.edu.ar
Date added:2018-11-09 06:26:15 UTC
Last online:2018-11-12 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2018-11-09 06:28:04 UTC to ipadmin{at}teco[dot]com[dot]ar)
Takedown time:3 days, 11 hours, 18 minutes Bad (down since 2018-11-12 17:46:34 UTC)
Tags:heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-109943.exeexe ed2f7f6a4c1ebc811a61a38f2b8f81e1561bd90e5cd628cf090e463dbe2cef9eVirustotal results 21.54% 
2018-11-10055200.exeexe bce8362f7dc2583eba7ece0ea01d9130634f1f84a1f6ab4a508666b215204c08Virustotal results 18.18% Heodo
2018-11-10157.exeexe 3c81807a2358dcbb9c613893c9e326bc112873f76ad2bded5cf83a4c03dd4445Virustotal results 16.92% Heodo
2018-11-10529456.exeexe 63f4506d521941471b109b59761d3f1708f8742eeaa9a1426799fdeeec2fd0e1Virustotal results 19.40% Heodo
2018-11-10156556.exeexe 2a1a0800059944c4976934d54c1daddbe9cf90a01b68a67a7679b03b6bda16e0Virustotal results 21.54% Heodo
2018-11-10962.exeexe 6a788cb527821b5780e61425f680c5b13aa5ba75b52536c7ae8c1aefe711cddeVirustotal results 16.67% 
2018-11-10274.exeexe be2031651fe7d2b573cd5f083f3b661ce28346e9c078a8497574f96307739263Virustotal results 15.15% Heodo
2018-11-0981884563.exeexe 62b9ce5605454260773d1dc35f57886658b7fde7f75a0229c63de0c3518a68ceVirustotal results 28.79% 
2018-11-091.exeexe c99753ddfcba80ec89bab83c59f074322cecdea193fdd3adeebcbd4e21d3d4e6Virustotal results 24.24% Heodo
2018-11-096.exeexe a921fd5974bfcc9b7133e30ef3ba72bb85f1eb02ded26f52a7d1bed576a6de93Virustotal results 20.90% Heodo
2018-11-0987309.exeexe 38b46887d7f7f17a56c3281ce386073e944cc257ecb1210c6fc4b8b16030c04fVirustotal results 24.24% Heodo
2018-11-0971.exeexe a67915345f7a32e7c40c51469a983ae18b731a658c04e370f2674ce8246c32ddVirustotal results 31.34% Heodo