URLhaus Database

You are currently viewing the URLhaus database entry for http://rjmtel.com/wp-content/bYAiTvGo635qKITG6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1976881
URL: http://rjmtel.com/wp-content/bYAiTvGo635qKITG6/
URL Status:Offline
Host: rjmtel.com
Date added:2022-01-14 16:47:07 UTC
Last online:2022-01-14 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-14 16:48:08 UTC to abuse{at}aware-soft[dot]com)
Takedown time:2 hours, 27 minutes Good (down since 2022-01-14 19:15:42 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-146TfEpP68xZe.dlldll ff7718dd83ecadba8e555ee21715a51c6ca646042f5b734b7d2f611ef2169d3cn/a Heodo
2022-01-14ij2.dlldll e142037756e3de86b13c6f9f5ac6cc81ed132a7191874ac5c4795ac7e4a68ad5n/a Heodo
2022-01-14WnA.dlldll d46762ba155e3345baf5d9e9453e6cd8e0647438693abddf34f98ae8d6bd436an/aHeodo
2022-01-14zzzUGG2539iMAcEK1U.dlldll 4bbed405f6dddd837d8302dfdbeb7bc5dc53f26758bcfffc26e2274c6eb4580cn/a Heodo
2022-01-148qt6iIZneN5.dlldll c60f1cfb28cc7e8ed3b5f1b4121c4d4e548cee9be66b219fd4b50378b818e63fn/a Heodo
2022-01-14t99yP2.dlldll f9f59107e635175f0d28eaf583d07b54d7fe847f307180fa32e83054692c3b60n/a Heodo
2022-01-14gW09oYdFrOOGHU.dlldll 6b1e5ad653432573be1a7afc8b119dc595daecfc3eeda5cd600efa0fa7584531n/a Heodo
2022-01-14QFjqfcmL.dlldll 1c9dad6b7e7af1404f3aa7449b71bbcaee943bc2727f9065c5235f2c9085c79fn/a Heodo
2022-01-14hG7QoY.dlldll d59ba5c38812ee2c17f92c21b6e0b536ee429b150aa15346075154b184f28cd8n/a Heodo