URLhaus Database

You are currently viewing the URLhaus database entry for http://secretariaextension.unt.edu.ar/wp-content/00002/WYXvv1vV which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:87116
URL: http://secretariaextension.unt.edu.ar/wp-content/00002/WYXvv1vV
URL Status:Offline
Host: secretariaextension.unt.edu.ar
Date added:2018-11-30 00:02:10 UTC
Last online:2018-12-07 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-30 00:04:06 UTC to ipadmin{at}teco[dot]com[dot]ar)
Takedown time:7 days, 16 hours, 42 minutes Bad (down since 2018-12-07 16:46:27 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-011448947.exeexe 7a193445506edfba002de1305d534512aa052417ebedff3829bf830b5289b528Virustotal results 23.53% Heodo
2018-12-012063.exeexe 2b17520c335cab50f989753f133e431f237d22cb026abd65f9811366d519e81an/a Heodo
2018-12-013240630.exeexe beec66b5326e2556d32efe285dd89c8f9e4fd777d113a3f8c2f41f6b0a7e3891Virustotal results 18.57% Heodo
2018-12-01887.exeexe 58df74bcdae05c274aa98ee222370705ace7b07f9c213658b5021059317a7c32Virustotal results 20.29% Heodo
2018-12-0115.exeexe 757b7972d0c39b06722025097e00366ebbdc184a3b71e3b5ef746b58ae7aa89eVirustotal results 17.14% Heodo
2018-12-0136.exeexe 1d35d4abb5001af925fc237726221c809ba65e8bdd0dd7f1ec1a55a23a38d486Virustotal results 17.39% Heodo
2018-12-010955807.exeexe 2ed804b62a00797d5451138a2f0c88fc48c4cbc7da4da7a73414c9ba4e6a12ecVirustotal results 15.94% Heodo
2018-12-011580003.exeexe 7fed4f467b5183228b17bf489519610315349aa54d828d114a4ee18fae73fef6Virustotal results 16.18% Heodo
2018-12-018533687.exeexe bda931a913ab444ffacd6def207f65d33fdf356752bcdb9acab808006a0e1131Virustotal results 15.94% 
2018-12-01885.exeexe 9f1202e881a7ea742144268905635d0244ac38292e24dfebb2d771cad7c500a6Virustotal results 19.12% 
2018-12-015994.exeexe e8600f01c991ba91c41a98a34791bb92bd81a528707101000eb47a9366f00407n/a Heodo
2018-12-0156713.exeexe 312eb2fdc962bb2aa3859f1eabeed586149362c580faf19eea0956bf25f53792Virustotal results 15.94% Heodo
2018-12-0111223.exeexe 42e67b3940772c95ec85d54bdcf03e3b9a146a118432e83f8f1498313e1ed7d1Virustotal results 15.94% 
2018-12-019954.exeexe 6857aac193b23e9f8c3c135abc4e6988f9d7c9a9cea66c4412163b3ccb7510f3Virustotal results 14.29% Heodo
2018-12-0144525.exeexe e0a28ce86b828aaeedbad2f4cfc6d6cb38c6e8b9630bb27f00e3d5710ffa6d2dVirustotal results 20.00% Heodo
2018-11-30654.exeexe f72213960a380dd022536b2e3da0c0a2ffafa336eec1bf98ce01e7cc664f9c00Virustotal results 30.30% 
2018-11-303.exeexe ff43a7ee91199cf00ca77eb615f6ede1242d1b21e5a9d6cb5bc59190e34acc34Virustotal results 20.59% Heodo
2018-11-30026847.exeexe 1697fbb63c7b3db8837b2630e925fd39210bef462570a9d256f225b85cd7c1feVirustotal results 20.29% Heodo
2018-11-300214.exeexe aae95e8f2169419538976f474ede4a67799c9a8658924a09a23045805d23a806Virustotal results 21.43% Heodo
2018-11-306852612.exeexe 16c7e688c4f182e81abe93a27c37c199b23d3caa5e2aa19b33b5c0ffa4a70880n/a Heodo
2018-11-30315.exeexe cf53b7bf8736cd77927888e3d8327103c79e95768ded1f2678016bb8c3a5630dVirustotal results 21.74% Heodo
2018-11-3038175.exeexe a6e52e4b0b8c2bc2d91852d3d85031483229432fce63d979d7c121c8236350c5Virustotal results 28.36% Heodo
2018-11-3068137151.exeexe d3cded230efb0e6a973a4e8435a71c2a0ceb9264e3bfffc052f078bec6064e2bVirustotal results 23.88% 
2018-11-3024628817.exeexe 47f9b7f01b4233718e90bcbafa8b5136c283b113189f2f1e9e0f3481ff0bd209Virustotal results 18.57% Heodo