URLhaus Database

You are currently viewing the URLhaus database entry for http://onetechblog.tek1.top/MyZztFl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:98314
URL: http://onetechblog.tek1.top/MyZztFl/
URL Status:Offline
Host: onetechblog.tek1.top
Date added:2018-12-20 14:44:11 UTC
Last online:2019-04-04 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-20 14:46:02 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:3 months, 14 days, 13 hours, 31 minutes Bad (down since 2019-04-04 04:17:35 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-20this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-20OHvexVggeBEV.exeexe 1f4a4f15511d2dcd86f5f6510627d57f6d40bf27a2347c6446ebe3f3068b73f2Virustotal results 22.54% Heodo
2018-12-20g0XpoWNh.exeexe d284d8176cb60999511d23e63bb015816cab930b937ccf9568af42b185f6bba5Virustotal results 23.19% Heodo
2018-12-20vSVbWUiWHyVa.exeexe 0efbab63e2b0e4053a5bd65225795d335df66c8d84d0bdbf2c68a54d95897677Virustotal results 23.94% Heodo
2018-12-20YZl8fC6usDEO.exeexe 1a49ba87f363e3377b3da8bb6a86f58d6d5c13aafcf6447b74d40ed11e974f86Virustotal results 21.13% Heodo
2018-12-20uTEhSWrgGwf.exeexe 02e6fa9cfbc5272b47cde561477c46d553f839ea54fea1df7d76e370021b4da4n/a Heodo
2018-12-207WtTfR2o.exeexe ea6214e9d84fd4b33306a94568fedffecceb8cfb60022a8985202c60b5764fd0Virustotal results 20.00% 
2018-12-20Shh604C9YBT4.exeexe f020910684e6b806586131e30692ffe070442a0288d67ff85e6506b97b86b6abVirustotal results 22.86% Heodo