URLhaus Database

You are currently viewing the URLhaus database entry for https://gasket.digitalcitrakreatif.com/hhkq/y4ltyrIuJJDvHlKyTjGAvcC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1863519
URL: https://gasket.digitalcitrakreatif.com/hhkq/y4ltyrIuJJDvHlKyTjGAvcC/
URL Status:Offline
Host: gasket.digitalcitrakreatif.com
Date added:2021-12-07 18:48:29 UTC
Last online:2021-12-08 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-07 18:49:12 UTC to abuse{at}digitalocean[dot]com)
Takedown time:5 hours, 56 minutes Good (down since 2021-12-08 00:46:07 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-08X9IgoP4IAebYZZlbu.dlldll a1a3c90e58be5b9a7815a2f004c55075bbca4a5398008b90db56fd02f83beb13Virustotal results 13.64% Heodo
2021-12-089Z2O8.dlldll 4d22d3c92f253167e688d6bf8047ea10bade919f63efb8c4ed3602205f45d627Virustotal results 13.64%Heodo
2021-12-07FzQQIsxuJgnwkRvtV7L.dlldll 4fb58d658f7be1575bbf4e9f059d6d6096ff7116119cf6b86bdb20d573317295Virustotal results 10.61% Heodo
2021-12-07t5eYB1pBhyGOvUBl.dlldll ce3074cb2e1d5bb2099b1c7769690eb1dbc8f62a2ee9612d9a23b4dd5f930d9eVirustotal results 10.61% Heodo
2021-12-07ie5ySA.dlldll 6af0f57b38bad0e51d1a3f4990e88d7a69ca1fc772e1a336f313cb4ff123b3a5n/a Heodo
2021-12-07F2icnRBjT8zOFPkWTe8.dlldll 9c15c5a2681ddb49e6639cc029b73b125b0d8e5b03e98565c1b193af13a70249Virustotal results 9.09% Heodo
2021-12-073qjN.dlldll ca9ed94023921ec514ea886d7bcefffc6b7d338683fc9afcf4549bf7881e7420n/a Heodo
2021-12-07uJtYK6w.dlldll cc30e5f555367e42c584dbfff14d43772e8a9dde13f5072e603a58529ff9ef5fVirustotal results 9.09% Heodo
2021-12-07gCPWXhnrLrpdRJLYPD6E.dlldll 870d6770effde8fc3ceedc1263903e7afdd48e38d6106a984a0a510eb8ba2e66n/a Heodo
2021-12-07TqYJ3277.dlldll 13a125dd0443fe7a48ea144c6fa1e4eff68cccd4dd75e2a3679414c288ef22a2Virustotal results 9.09% Heodo
2021-12-07vVYxuQy.dlldll 63211d2f599e262734ea2c575dc1127b6340391b6ecd517af69b8c1141395602Virustotal results 9.09% Heodo
2021-12-07C4km4s3K.dlldll 395fb089b9d251e1a7c35d27a1b72b0174629613190e94c2d5ef26be624b37d1n/a Heodo
2021-12-07N8Y3nAv5oH0Kdwar7.dlldll 3f98ca932f63009fb8038d608f77e2f93c3180b8a7216f4eeffdbdabef21e356n/a Heodo
2021-12-07XUKKhU2fq80.dlldll e1d24f6e8cd65d8259ed8764657bab473352bbd984df981a80ff8c4e10684599Virustotal results 9.09% Heodo
2021-12-07lX2tvByFYWfHaEXARL.dlldll 8abba113793861afd4fd24492d8424938d11821cfc3987ce5a1142f53d5d15ccn/a Heodo