URLhaus Database

You are currently viewing the URLhaus database entry for https://alignerpliers.com/er1lrd/28DnnQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1988749
URL: https://alignerpliers.com/er1lrd/28DnnQ/
URL Status:Offline
Host: alignerpliers.com
Date added:2022-01-19 07:37:08 UTC
Last online:2022-01-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 07:38:35 UTC to admin{at}frantech[dot]ca,fdias{at}frantech[dot]ca)
Takedown time:2 hours, 38 minutes Good (down since 2022-01-19 10:17:04 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-19eHWaDtV3DRQ.dlldll c543e5b9cc888708c4588474dfe01a0011b70141192205e7f709e0149bbca2f1n/a Heodo
2022-01-19gFMjjTVGxqE27eOhx3.dlldll 478708c06367185c9ebf03fb7c8a382192189b9a765e972edf90212c97a44838n/a Heodo
2022-01-19EM8rNr88Q.dlldll 5d34c84b4825c0c76cf470fb061e5e070de12c1f9dde7c658bf3adf7f1760806n/a Heodo
2022-01-19loZZeNBEmEc3kG6Gi5.dlldll 17051860fd79f361f17b1487638760d6f6564ee45c1fc934a10187590a8bea35n/a Heodo
2022-01-19tLG.dlldll 44aac93320932a26db9f841190c6475a151c17892dad4eaac074eadb067cdfa2n/a Heodo
2022-01-19pBwV.dlldll 5577c3e50719ef25a7c17676665dd0074ae7e09a14272a481964acbf960f532cn/a Heodo
2022-01-19NK2jWu2Gj.dlldll 40132ad254a2b6cdbae100f7803c26dcbda653de57d1acffeb6dac631ceff73en/a Heodo
2022-01-19ccF.dlldll 5df4514da0fc7b3450b710fccf6f46d4bc835b06326772ea652cebcf0b05f1c9n/a Heodo
2022-01-19rrhvB9MbLwv.dlldll 2571a48994d72769f5c1a4c1e4985d4148c7406d692d63129c28c025290559fdVirustotal results 28.36% Heodo
2022-01-19WuWpzO08.dlldll 328e3100b95edb397be40206102e286a9dcf059f94916bcac8c64cc9b2ddef0dn/a Heodo
2022-01-19t8yi8AIBK7T3gN.dlldll 97a09bc2fb84764d879881eff9aa802254bec013be5eaef92536051119dfbaf5n/a Heodo