URLhaus Database

You are currently viewing the URLhaus database entry for http://lomidze.info/gnh_enS4q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:97643
URL: http://lomidze.info/gnh_enS4q/
URL Status:Offline
Host: lomidze.info
Date added:2018-12-19 07:31:13 UTC
Last online:2018-12-22 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-19 07:32:07 UTC to alternet{at}alternet[dot]ge)
Takedown time:3 days, 2 hours, 27 minutes Bad (down since 2018-12-22 09:59:56 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-19this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-19jHwcQR_j3OhvSyE.exeexe 5321e0bfe9a3273672fc9e2d1d57feec4a334f42dcda87445f32d522d589f1c8Virustotal results 25.71% Heodo
2018-12-193_kDk.exeexe b15c68237ccf9b9c848d505807254bd68be1d31f7dd312689603c47e600fa41bVirustotal results 27.78% Heodo
2018-12-19D26IAzW_3FR3befv.exeexe f9cbbd40feda5ad4daae5caeb83fd383f9fdd4e3242214a9009884c50ea19df9n/a Heodo
2018-12-19hw0_M7U0MaTs_z.exeexe 4351997cac5515c936f357f7d0954e54774c62ecdb46f959ca6af1245a711f0eVirustotal results 30.00% Heodo
2018-12-19rPZ3Wvs_dlQD.exeexe c1a16532eb71463c7a25bce43f146da857112cedb5570cab38cfcde45bc9e6c1n/a Heodo
2018-12-19btbmbQX_dPRQvS_8c5JGVIK.exeexe 0fd8b90e37fa04c52970fee323549bfb63e5d129990ff0bb78534b426d286019Virustotal results 28.17% Heodo
2018-12-19SX8q_VOKLGGa.exeexe 091f45880342ab24bf77dc1fdf9b8e3ce0781b9be995d6827f56d5749cac5b3cVirustotal results 25.71% Heodo
2018-12-19hCZ_kviuoUw1.exeexe fb17c620896310aecf97216fd4cde71b0b3e45ce96e1eb7110f0fa071d25858cVirustotal results 24.29% Heodo
2018-12-19C_NbD40QmD.exeexe bb24d9d2d9e313d364311e455abe2443bc6ea46d1a49d7e67673978129cdccfbVirustotal results 23.94% Heodo
2018-12-19LqR_ktsI.exeexe 6270f3b0b283e20edb44a437015275a71ccd654b08d8219ef200f9c6806af856n/a Heodo
2018-12-19N_QObLt.exeexe 92df5ceafad4790a74eddd1bf9274a29be54874af791b8bb72714ae9a24c7d1dVirustotal results 28.17% Heodo
2018-12-19Pi1I_nnG.exeexe 7eba255c926e9d59c8f344b7b167cbe78f475ae16384d27f8c29e37c559787fcVirustotal results 26.39% Heodo
2018-12-19O_zlhR4Fr.exeexe 0563c0b02e08f13848a16c252817802d5d1f4fe7e371ab0c7b594587ee110a7aVirustotal results 26.76% Heodo
2018-12-197G_60uY5YZgJ.exeexe 4d4eb71cff0df2aedfcf18d12163bc2baecc71b0c6ce79bbd0c61d4eff602137Virustotal results 23.19% Heodo
2018-12-19OZr_4iBDhZG.exeexe e844b9daf0f12ed8c1a46a7a3b52dd928ddebffec3beaea4d4d8e236161b9dben/a Heodo
2018-12-199TTQk8K_iLU9Jq.exeexe c12cea4f57b824206ab9e80f892bed1eff9ceec1da535ba31904f34864cc45dcVirustotal results 25.71% Heodo
2018-12-196Io_vY6p.exeexe 37eebb40d4f04bee15e938d3c10a2f8c1e6a6f3c687a361c7deaa5bd85d5da75Virustotal results 24.64% Heodo