URLhaus Database

You are currently viewing the URLhaus database entry for http://teachingcenter.xyz/ultimately/2lfBWlgxo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1837853
URL: http://teachingcenter.xyz/ultimately/2lfBWlgxo/
URL Status:Offline
Host: teachingcenter.xyz
Date added:2021-11-30 16:29:09 UTC
Last online:2021-11-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-11-30 16:30:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:4 hours, 26 minutes Good (down since 2021-11-30 20:56:44 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-30JfrVbzw9F0ORDPiF5pfc.dlldll f59e804e0e8db7786adabd23a5bd75114769cadcc81e867d9577c669b579d8c3n/aHeodo
2021-11-30HEHMQ5XkUW3.dlldll edae77dbcc50e5d7e732068487dabde14505ccfdb4db8b410b40c0ad528d09c7Virustotal results 9.38% Heodo
2021-11-308pNkAP48NJRyWTKEWNkM.dlldll 55b6206c77193220ef510f6636afce46835f437f84000eb4afee379c6773ac6fVirustotal results 9.09% Heodo
2021-11-30bmxqSdoJ6a4IZ.dlldll 127deede0ff5beeb58be669ddf1f2fc35e370e5ebff0dd5f294ad54bdd97007fn/a Heodo
2021-11-30dmmm.dlldll b30d7f4b78145fa2cc45a66c769ccd5cb76765f6647c471c5cb15e767ad79daen/a Heodo
2021-11-30IEJT1EhOQkl6m.dlldll 0bac1fffc9b41d023da98282f87525b29c47c057dadff288a23d29bea3374ec6n/a Heodo
2021-11-30RrciZmSgGiMS.dlldll 11d9984b8611804348d927790a5e53faa6d8284371ab179412590d447296deacVirustotal results 9.23% Heodo
2021-11-302Les.dlldll 6b5943079e79e8c017577c5ed94e5841bf54f31b1f78a4b20e7b456eb04026adVirustotal results 9.38% Heodo
2021-11-30oawNbifkYoFhmRrkpZY.dlldll 1c7ec7b4a22f5571c9915ad4d9cb2d80229fbc77fcddae04defb5007c6973c6dn/a Heodo
2021-11-30qbwoQK.dlldll b9083ff1eb08a447cde68c4494e8bd9963e5fd10ed29bb4a59a98c58441d1ab3n/a Heodo
2021-11-30Dqhlm1H1WO6yznMq.dlldll 307c229ee2094c66eb51351c766d777147f776ea91e1d06b0e337856f90a2ed2n/a Heodo
2021-11-30wusWNrsk.dlldll 533ca7114ad74675ebb9f29125fe24ec2e920ea2e287f2bf464bab47479ff883n/a Heodo
2021-11-30RZW37.dlldll aa42f48223a73424a8446cc6e1e0f8ca4b44d07822e46c739034d5ed79d3165cVirustotal results 9.38% Heodo
2021-11-30fzCkNcZvG3d0zW.dlldll 9ebb77d6206271d05eb6642d756b2f7ca399991afa2f3b4a6119172b89291b8fVirustotal results 9.09% Heodo
2021-11-307dhZEOwj8TMuzyxw.dlldll 1dcf783e093312652531158602a705c1f4438b08eee4ec081371e989addac294n/a Heodo
2021-11-30wLkEJrDiCnwKmHi.dlldll 502086a415f75695506f1fdaa5824b8cda68dd6b0d2c2bf4ddcd3ceb213199c8n/a Heodo