URLhaus Database

You are currently viewing the URLhaus database entry for http://knossosclothing.club/amla/bk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1845869
URL: http://knossosclothing.club/amla/bk/
URL Status:Offline
Host: knossosclothing.club
Date added:2021-12-02 22:43:11 UTC
Last online:2021-12-09 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-09 00:26:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:6 days, 11 hours, 32 minutes Bad (down since 2021-12-09 10:17:14 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-03mw3PCnOe4L1.dlldll 16211b428f9d5da08b3a0d77589bf217f34558388d52d294f7d37dfe5e44b2e0Virustotal results 12.31%Heodo
2021-12-03sHU8J35h1UrMFiNr.dlldll 72856a1bde8683ad1eb96f61aeea52fef754c48efcc76de806d8b6990821aeb1Virustotal results 28.79%Heodo
2021-12-03z.dlldll cd9419510c772ddf117334f1b3b2f987fe3d795351d2dcedfb76af765ddf17bbn/aHeodo
2021-12-03ZlNQg4mYHhF7cj.dlldll d35cd5412ffdc0388763bf9c5807c6288fbb1831f3556f47f0b59af568564f66n/a Heodo
2021-12-03rufFrssYFv40k15eLU.dlldll 1fd9ebebdf748180e4a675a64f3a9b6d70dfa805781be7918d85ffd37c6011aan/a Heodo
2021-12-03YtqqUG.dlldll d71850f9819986c0cafe85703f6801a87909530f4decaf71d92dbce58afd89c8n/a Heodo
2021-12-03TRebi65IP.dlldll 989b5c384efe50ff071a98378e7b723c5a94e8b0ab7150b38052bf81e273effbn/a Heodo
2021-12-03xM8gWz.dlldll 2aa61c3baa5b0dee9f1cee736b865775ce0ebe97c5b24afec299d6bd5fdfc908n/a Heodo
2021-12-033dgcjiKjS.dlldll d83e7c6d70be4d3a11ae88df29aa4755ec6a2473f744953887a083c5ec363b7cn/a Heodo
2021-12-03lzkQTzcaNw.dlldll db0db90740a0243ef34680e507dc530ae68234d8bf6389dfaa22c54b4cafe876n/a Heodo
2021-12-03GIdcTMfPjxepO7.dlldll a79aadff2bd2480943ce8d215c247ccffbbc633e86a2eadd948985735faffe09n/a Heodo
2021-12-03WldtUTNPwpRRT.dlldll 4386eaeed3e833940301a73568d5fec30ab61e34b2f5349891e76a7633fc208dVirustotal results 13.85% Heodo
2021-12-033MvxEftjLGyXhZ92k.dlldll 0356dbc9256443070c8c4039377de0843f9835f5da621d12164f399bf4a70bcbn/a Heodo
2021-12-03WxgosvTYXXpo.dlldll d0adb115e29b32a3073512f1fd8a0e2e8203504f7f9ef8541c6db032f29a1769Virustotal results 12.12% Heodo
2021-12-03hiKV9UoEpu.dlldll ab79c143d37aea7424c168fc006800f6267722e8457cf8a301d4c3f505300f35Virustotal results 12.50% Heodo
2021-12-03WBgaaa7OTzH.dlldll 9ef5bd0ddf6ce30a0a59be5ca1c81d97a27995b8191a66f9cbc480207e315250Virustotal results 12.50% Heodo
2021-12-02lrRUtAU.dlldll 0727a5c6cf158ecdd576699291c5fb5c42a6fb8cb797656c120e7d33e570ca34n/a Heodo
2021-12-02T9ZppHEV.dlldll a46566a9cae02c1b04da80f4ff402727eb41ed0d8c0ab8f837a10d68cfa4f61bVirustotal results 10.77%Heodo
2021-12-02d.dlldll a1395881dadc3aa7a22b4659e3241781cab28c67281ad24b0abd735c249d4864n/a Heodo
2021-12-02yy4g2nfkTfuyupT.dlldll ce1730e00ab3efe0855098440e6e232943355a9d8696ec315dd1a79a2aff681cn/a Heodo