URLhaus Database

You are currently viewing the URLhaus database entry for https://www.monami.gr/wp-snapshots/tWtjDv6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1997914
URL: https://www.monami.gr/wp-snapshots/tWtjDv6/
URL Status:Offline
Host: www.monami.gr
Date added:2022-01-22 12:03:10 UTC
Last online:2022-01-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-22 12:04:34 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 hour, 51 minutes Good (down since 2022-01-22 13:55:35 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-22Zh.dlldll cec8ae3295687b19c12088c982960f8b8b08365327fc5db6682426e416c9a88cn/a Heodo
2022-01-22mb9o2Eo8i.dlldll 8a5e313fac03ca89ba291e18172ff4038588ad48f63f04ec205af4938adbcd5en/a Heodo
2022-01-22XNhu561xP82xv.dlldll db0ced1f8535e78dbe4cb8a90d1a04ae46f36ee44d7fe77c9dfd2deef9dbe563n/a Heodo
2022-01-229cuVHWFz.dlldll bce4bcadff75bfa68715ea3d33a9f216862d20b297e5843e349fc4ee02a2f804n/a Heodo
2022-01-223z8rZPgUvuuP.dlldll e168742bc13169990cfee17904493d214598a71a193137ba552940d279dfc81en/a Heodo
2022-01-22d2yIQsduk9Ske.dlldll bcc48b2ab39687e5c2442b2b1b75b243da7e0b7c9cffa1c22512ce51f88396f8n/aHeodo
2022-01-22v45Piy8iBTl.dlldll 34fc042c846a13aa82acf0e82f5c1f75cfb4dd43e58ad2587c21a0122a9be9fdn/a Heodo
2022-01-22r.dlldll 233145c792d6cbbc2e6398c83712695c4daf1291fe2023a1af9c6e3a660b27aen/a Heodo