URLhaus Database

You are currently viewing the URLhaus database entry for https://rezokretyen.com/wp-content/5USHNz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2004646
URL: https://rezokretyen.com/wp-content/5USHNz/
URL Status:Offline
Host: rezokretyen.com
Date added:2022-01-25 09:06:07 UTC
Last online:2022-01-25 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Takedown time:4 hours, 19 minutes Good (down since 2022-01-25 13:19:33 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-258AXPAFuU.dlldll f2d09d3512ddd00f0880d3d1d28882e0a19127d38be13ab5b7d9c140351f7045n/a Heodo
2022-01-259lbSkjQYR8k2i.dlldll 9ad4cc5a06b41dd993361293cde7316decef043c1a700f85feb352cca742a04dn/a Heodo
2022-01-25hii6M4zD48YQUnqAk74.dlldll 1818a4aaa70af2cf1ba7004199a3b88f2f8234a39af12ef7b05da86dd7e895dan/a Heodo
2022-01-25mdJJuBXr.dlldll d5e405dfa1e537601fab53809ee95e0317aaad573cd548770f13b029206e8fd3n/a Heodo
2022-01-25XXA.dlldll a9b008b20f7eccc49742d0ca5cd657a9d4f3b2822f74bf2757ea77db8a684fadn/a Heodo
2022-01-25W1BHK6XAow2W260RD.dlldll 7ba43abe9639bc02e809570363efbde6fa09e10f367ea5273571ac0a67e68875n/a Heodo
2022-01-25RHbuj.dlldll ab75a8991194d707a320fbbc09fada59dbfcfae01d196a584e429d6a6d74ea62n/a Heodo
2022-01-25SqdPEDWvzTbus.dlldll dc9abd78b0cc23fac50b8cf36cc81d182ca49f6dd512ca0e621159444de6cdc1n/a Heodo
2022-01-25zC5scc.dlldll c7d77b989d2b39bc6466f3a4a5d660c9fe079881fc5e6834a078de1656b5183dVirustotal results 20.97% Heodo
2022-01-25ALkAdmg.dlldll f6693ca73059fe2d63cee7c76f68da723a781aaf52bdafc0dcfad0a1858c81ffn/a Heodo
2022-01-25kQjEbpJ.dlldll 5fedb0cedcf68c4b91454acf841c2ad7362c2948008ab4d746bb049c46f44038n/aHeodo
2022-01-25DDtSVFF91PRMWtz6WPE.dlldll 2cb654365b9825a804ff1e378aaefefbc99d5262ec0ee43f7559d0e3394e0085n/a Heodo
2022-01-25s8PlpE.dlldll 79ea86a21e31f5da88a315687a79d6549e83c58781a5412c780c2702e1db8c5bVirustotal results 21.21% Heodo
2022-01-25GKSnaHKOSUO8Dqqh.dlldll 6f8e8f5f9b65d3ce2ddb06385e54b1641117b07787a24a20207c8cb14a035799n/a Heodo
2022-01-25QjkpjyLGZbR5qKVJsQM.dlldll 643f12986c4edc532640f9ac13043f64340edcab6a531bfaa07d8977f87aff47n/a Heodo
2022-01-25OM091QwD6DZqW.dlldll 41c3cceeb794e4f2f50cf6fe11420a91b4159af2a1befbf794d0961e55de510bn/a Heodo