URLhaus Database

You are currently viewing the URLhaus database entry for https://www.haeunkim.com/gerter/fanver.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:989599
URL: https://www.haeunkim.com/gerter/fanver.php
URL Status:Offline
Host: www.haeunkim.com
Date added:2021-02-03 19:11:05 UTC
Last online:2021-02-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Myrtus0x0
Abuse complaint sent (?): Yes (2021-02-03 19:12:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 hours, 4 minutes Good (down since 2021-02-03 21:16:09 UTC)
Tags:bazaloader link BazarLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-0317sfg5df.exeexe 140a09f7ed7393880b0e4de6f598e05efb06db2cf9c27285c8580da81f388671n/a 
2021-02-0334sfg5df.exeexe 2da9b9f5eb6c17b61deb03333a9cbfbc525e541af2285a208e55b8b840c3b1acn/a BazaLoader
2021-02-035sfg5df.exeexe feed0c1207e017e9d457b93bbaa887bfb34942e58fe34578eeee01fdebf7344bn/a BazaLoader
2021-02-039hsk3df.exeexe 9d50f36437092de23adcff4c6874e4c76498cf2e2b002aa7be3dea47fcc3a438n/a 
2021-02-0315hsk3df.exeexe 03e32fa599b7e93b8ae145bc6671cbee2e442daffa24a3b6ed9f85acfb217368n/a 
2021-02-0320hsk3df.exeexe d03fffa84d08f296d65b66d549b446a7b9ee228815dcb2d9e6a83f41c6c81e13n/a