URLhaus Database

You are currently viewing the URLhaus database entry for http://shopnhap.com/highbinder/UedVfTHDf5Em40/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1974945
URL: http://shopnhap.com/highbinder/UedVfTHDf5Em40/
URL Status:Offline
Host: shopnhap.com
Date added:2022-01-13 21:10:11 UTC
Last online:2022-01-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 21:10:57 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 days, 4 hours, 13 minutes Bad (down since 2022-01-24 01:24:07 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14AMYc.dlldll bb6109acc2b7474d53e223a5756822fb77b8b7495af31ffdeb90dd2e8584e17bVirustotal results 15.38%Heodo
2022-01-14yNjbJ3jfFh4.dlldll fc1ae126ac97392c78c144ef97da4b13fa5d9f373c5683270c21b1620d87bb0cn/a Heodo
2022-01-14GrJhp.dlldll 42c928ef31399b0f8914549b14a992010c2238b60a935fa4d12be0882fc23a5cn/a Heodo
2022-01-143P7yr9GQAJaSsAgM.dlldll 7eab81e51d67501f4843a603bb93ffc0c06ddbfa78e29472d291970694d5be78n/a Heodo
2022-01-13uiqC5WkgOWlrE.dlldll 40eda85a5ff6691c3b8aca67b3d55ef47a1427e02d5d8087db866304b0e8af68Virustotal results 14.93% Heodo
2022-01-133fqmRW4gYK1Hrryk3is.dlldll f57d7cd599d9f652ca1932a4eb106b10df4b700401488b6c3361dac24b6d2885Virustotal results 14.93% Heodo
2022-01-13Q0kvulXF.dlldll d35da1bfe02335276091890e2a1daec59c1b07408b0d3ee75761c75e792a3002n/a Heodo
2022-01-130yTaN6DkLw.dlldll 3f8b1860f7c2627ab7b5685999f9fc93d372dee100a781e0382828d57c239a83n/a Heodo
2022-01-13JHUeXx.dlldll 2e4a726187804612107b7a06c75153589bdcec3a54fbbebd99a30b66793cc28cn/a Heodo
2022-01-13JjiGiG0OEDBwLXWtVI.dlldll ba675995ad3b7ed22150f7bfd1d41b76436fddbe68f877a28d27e4c280735294n/a Heodo
2022-01-131zb156yEE2Xe8OHe.dlldll e161f1f14a6db73cd0b08044bc471fb6f158121a3c8123cb395623d9fa86e30bVirustotal results 20.59%Heodo
2022-01-13DFTGVsY.dlldll 19af3546bd7d047efcd3f571c126c4b283f6e537a19bc6b62f7d412068eacb0en/a Heodo