URLhaus Database

You are currently viewing the URLhaus database entry for http://thinglabs.xyz/overcollar/s4rNtArh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1845872
URL: http://thinglabs.xyz/overcollar/s4rNtArh/
URL Status:Offline
Host: thinglabs.xyz
Date added:2021-12-02 22:43:15 UTC
Last online:2021-12-02 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-02 22:45:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:4 days, 14 hours, 19 minutes Bad (down since 2021-12-07 13:04:59 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-03UjVN.dlldll 16211b428f9d5da08b3a0d77589bf217f34558388d52d294f7d37dfe5e44b2e0Virustotal results 12.31%Heodo
2021-12-03o8thEG6LHA.dlldll 72856a1bde8683ad1eb96f61aeea52fef754c48efcc76de806d8b6990821aeb1Virustotal results 28.79%Heodo
2021-12-03Mb.dlldll a100ff92517576acf503e784e1d6244ed50fefaa881d33069eabb984b731d02en/aHeodo
2021-12-03jViJnzEnwHKd.dlldll a927cf5b92837ff59e4c8c366fe47798686d77164d5e6fbe7732b894516c8e65n/a Heodo
2021-12-03qC1QdlE.dlldll 6e91ab48ee46d6834d44a88f0b61674f6dc7b067af789e26c53d09bbe06faedfn/a Heodo
2021-12-03OR.dlldll fa1f0450557d9c8f25559f30921d92b966693f03a60e02564ea291f3db39ffc4n/a Heodo
2021-12-03ySVsh5MoGdypthIUB.dlldll d3e93b7c34b6572788b26ebcb3cc55cf099af40ef3c50953278b5099d1946623n/a Heodo
2021-12-03a3KX3E0jUVj.dlldll b955610ea5d85d1dbc95a3e006df3dfba4adf413360cb991bdc4ff2cf1be397bn/a Heodo
2021-12-03svZD78V8LHILaTic.dlldll 3e4fe6cc2f144a91fea43fb703c480d43d12568fc08480f52b1827d0b326aa96Virustotal results 14.06% Heodo
2021-12-03v5qp5li1J0NGf2K4.dlldll cafae53a0e4bfec3563f4022bf20b1cdc162d4323c8fc581093ca213a8ad5deen/a Heodo
2021-12-03QGZPN8KGZF.dlldll e13b19f1a78bce9b5d29f160d5ebec2b70ead466b5236244b9ea967f0be5672cn/a Heodo
2021-12-03zvq8ZJ.dlldll 7834875391cbbcfa83693f22cc7f0fbf27a3d36401268bcc505bbc384782d4aan/a Heodo
2021-12-03lt.dlldll 1809f68e8f2bd0acd153ff7116f94b82dd255f000661cadff5b41855a12cbbf9Virustotal results 12.31% Heodo
2021-12-03mXnuqXVdxT3n1qm.dlldll 2523bdafbd3c9a94b1ed72a4696ba8638b42bf9a32d5a8084af1b471e6a4f959Virustotal results 10.77% Heodo
2021-12-03sssx.dlldll be8ed0eedbf25d9d8aa1ce5b0e7585bad0ff03ff70ab7a825ec7acd7d8f57275Virustotal results 12.31% Heodo
2021-12-034nkUrpzy9xTY9w.dlldll 722a6bd5f09cbd16880f8a089362c229198ff99fdbea6692aeb77c776ff24c1an/a Heodo
2021-12-02Rsl.dlldll fd45f9c49a02c178acbbe9262003b5b2a9ee9393505af7bcf1bb1a66b2040e54n/a Heodo
2021-12-02SUgerLJSNNQnkV.dlldll 13cce288cf5ee7e304fa935a4a74b595ed338da0090e771c21c7bb4e232d40a3n/a Heodo
2021-12-02gwG8X7DSDcMuQTYDGG.dlldll 413019e089befbca507a12027f88e021e53e370075cbf2a3f4bb3c9d37e027b8n/a Heodo
2021-12-02yH3jfQE8.dlldll c3e834edb5f8766b9f2062065e5a63fafb808a8893ea63a3cbd42c705a9f9c37n/a Heodo