URLhaus Database

You are currently viewing the URLhaus database entry for http://shawktech.com/GxEjgOLcp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:89390
URL: http://shawktech.com/GxEjgOLcp
URL Status:Offline
Host: shawktech.com
Date added:2018-12-05 12:28:13 UTC
Last online:2019-04-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-12-05 12:30:03 UTC to abuse{at}godaddy[dot]com)
Takedown time:4 months, 24 days, 20 hours, 37 minutes Bad (down since 2019-04-29 09:07:28 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-27n/aunknown 474085acd31681d171eb64b4b120db857aa64f226653f0fc3ce4281caa776d6dn/a 
2018-12-05UfAG7FJq.exeexe 8184aaf870757bb977f1b72d703d3df2e75570519be6659d7cee66e20df5be39Virustotal results 20.00% Heodo
2018-12-05oIxqx3MT.exeexe 0addcca529f446bf60ea7e7c549b3e4d5d658c9e1e25ec0284029093167da58bVirustotal results 24.29% Heodo
2018-12-05AFqM9yvL.exeexe c906761eada01b61c5c20a38410d34f767369102366a51b3ee083c09ab0ae838Virustotal results 20.00% Heodo
2018-12-05ezSf1iOe.exeexe 9227493320c2d5e55cfbb7b27e67a8d2176ef4a0880356421883543d7d5fc8e3Virustotal results 18.57% Heodo
2018-12-05raCpC6nZDku.exeexe bb0ad2c1dc2c13fefeeb3f39499878793a5c074e7bcfea11a4f2c8478bc2af2fVirustotal results 30.00% Heodo