URLhaus Database

You are currently viewing the URLhaus database entry for http://goodmarketinggroup.com/live_site/Y9cEk9QNlDUeg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964739
URL: http://goodmarketinggroup.com/live_site/Y9cEk9QNlDUeg/
URL Status:Offline
Host: goodmarketinggroup.com
Date added:2022-01-11 10:19:06 UTC
Last online:2022-01-11 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2022-01-11 10:20:09 UTC to abuse{at}a2hosting[dot]com)
Takedown time:9 hours, 36 minutes Good (down since 2022-01-11 19:56:17 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1153Xuqf.dlldll e783764067a266d15776a5ec1677e3c537e1bdd64db7bdb877fecccf22b1cc71Virustotal results 13.85% Heodo
2022-01-11mmzBqLzIX.dlldll d7b64f1e4314eeb29657cb389132003425f3d700e1c3c4b29afcfd4aaddfff81n/a Heodo
2022-01-11BEW.dlldll 056682ec15850024cf317f082e69b91486344216562526c454b34ed900c06322n/a Heodo
2022-01-11ANHonnfNtwXorj.dlldll 584a7b147237b44855db2a5cfb6cb0a548ddd1f96d73bcaf313bf8a6c452af26Virustotal results 22.73% Heodo
2022-01-11r5wFC4z1.dlldll 8f3fae9bfc7f6dabc49de6ffbcafedf513658b66087c0e051df058fbc6a72794n/a Heodo
2022-01-11IuzjCSYAP.dlldll 7e4d5d641121a56ccd334a19fc78bb036f6e7d7d7cdc4a2fb3c897f436a140edn/a Heodo
2022-01-11fTU5v3TYFa9g.dlldll 1ada3da1b165cc8d9f81b4fe1c157f55dd69c27e42e09c9e68c2b79fb686869an/a Heodo
2022-01-11BDB4bU.dlldll 05971b987ac35f3839e64f51238d98097f440c4281fa640e1196ac67814c1160n/a Heodo
2022-01-11cp.dlldll 87b168d2faf08e74115d966bbe695639e965a8213eab1a850d56b5020aa9d43an/a Heodo
2022-01-11If1TFmbX3r.dlldll b4100db29f3ab71d5ea23c906b52c4b0aa2e8e6b9f90ea442d44387479b278ebn/a Heodo
2022-01-11eMEEoH.dlldll 1cba268ba319b11c2fed0f08f0b73883ad16086d23a0acb140158bb37fde3ee0n/a Heodo
2022-01-11yMxuVoKy21R8L.dlldll f3445b6be5308b36c053c234d7fe16457d23d1a2be4154127bedaed1b791e9den/a Heodo
2022-01-11fdQVjbPWj3rxp.dlldll 56b8267cb8d9e8bb653f959e79ee5cf268129bc3e9197ed53e19a602fd9fe839n/a Heodo
2022-01-11cOi2LY7Uc4p.dlldll 306f987e91fee0ce1b6edbf430fce76ee8c2155eb0685304f46a1f122193c492n/a Heodo
2022-01-11C86TQx.dlldll 961c67bf4894228e2691e7d4eff29d9947e573c824966bd2adfa49b426d2b3edn/a Heodo
2022-01-11vXaaFvqI9oPsR3nr.dlldll 359b9265c09df240cb72a029d7ca2f5ea7aa0cc801da2e7e19203fa400476e89n/a Heodo
2022-01-11JEnuuR7EEAsT7N0.dlldll 680bc832f92dda6e5d61c93ee31875c5f1a96c542e80225aa4832a7413886cb8n/a Heodo
2022-01-116GuLT6Dx.dlldll 45111d02a96fb91bdb3f8608615e02fd77a338ad710887b8549500976934a685n/a Heodo
2022-01-11by3Tyz.dlldll 351b8e4a571e33b63789143660c18d0ac724702422edd59d9bf268de86f11fe5n/a Heodo
2022-01-11SBr1neg1OK8UHjfOA.dlldll 706c4abbee5c52ed479b3d3d5dbee3d644373cf99fad40c91a755a4fb9e07290n/a Heodo
2022-01-11WUbqVDKsxDa1.dlldll 30298b4175f49c4c45bb5ee64e04c498b7f5d6186e3473073a31923b30a74756n/a Heodo
2022-01-11Zf6m41.dlldll bbf85fbaf26dbc9684eabb1d1d755d6816bc8cfdfddf8e02fb81caf5aef585ecn/a Heodo
2022-01-11YHvQmtP0.dlldll 51fa6fa68aef184733c8f3b2ed53031f4e3f16464731aa921e86ff4e94c4d1b7Virustotal results 7.46% Heodo
2022-01-116YFEN.dlldll b2077278213f67bc02e3851d505345bfcc29c9101d61cc9d4cb20e3e7d5d0b0dn/a Heodo
2022-01-11xcnxK.dlldll ea52c8b48ff6ee1d835f2837ef75a95cc8af36f98cb1657f82cbcdc34df5f135n/a Heodo
2022-01-11lEdExXyt7.dlldll 2fd5fbbee422e84f8a6bd375095b6b14fc9966799c98da656bdec7ef3454bdbdn/a Heodo
2022-01-11d3e.dlldll 7900239dd6722b7951a342828d62e7b6556747d275f13bf9da22a41df9a0ff35n/a Heodo
2022-01-11qUW7ZdfH5XBmyYYcT.dlldll 94bf12b0b79a4be1f61b3117b93974d3655506ab354c0d3a9d31086b195e7a4bn/a Heodo