URLhaus Database

You are currently viewing the URLhaus database entry for http://russian-coins.info/libraries/8oDzr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2005294
URL: http://russian-coins.info/libraries/8oDzr/
URL Status:Offline
Host: russian-coins.info
Date added:2022-01-25 14:32:16 UTC
Last online:2022-01-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-25 14:32:43 UTC to network{at}abuse[dot]team)
Takedown time:19 hours, 41 minutes Good (down since 2022-01-26 10:13:51 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-26Zbyk13.dlldll b386d04ca8a50a559e1a246208f16ce781977d880e30e76bfab412e870af61f9n/a Heodo
2022-01-266xFNp.dlldll 49270810d05b57c88ebb79031921ceba4065e55767f3b96f04ab3d710dba94e9Virustotal results 27.27% Heodo
2022-01-26DGTBFrlfpsMcdNvO.dlldll b889630bce09e913717bac41fa4928bb186f4659d5ac4034d62d751d7b4b4f43n/a Heodo
2022-01-26TTKz.dlldll ed2718117f67ecd2a4111454e9bebfe0ac09c4302c39d519af6e260c0bbe45c0n/a Heodo
2022-01-269zxV7YJm8HkK28FHxFw.dlldll 3d547dd6a47ff19536976619ee6e024471a8e02e7406716f8f3f1d9885c9b2f0n/a Heodo
2022-01-25ZvRZPr2gVDdMWfXxB.dlldll 531fbba83c39416002e404dbc720e27a2a5ccc82909625532a0a19a61a09a147n/a Heodo
2022-01-25GH8P91.dlldll dbbdc43ed30c995057e4040149e09a782c44c3959d37b56f84e8bc1c0cd59298n/a Heodo
2022-01-25HsDVCVV.dlldll 1463f8665d02114d1a2add8a5f16bc08acfad3922233cea3337a323e6ac4a6d8n/a Heodo
2022-01-25bcc15Rxs.dlldll 9ecbf7909b42e9cbe2259dbbf3a7b9749c0e1a40f51267a5dce513d8d67eb65fn/a Heodo
2022-01-25r3GstxvcaL.dlldll 9b8a2eca64020bc371da8197868e3a56cff04e285f353300b53a1b56bccf3a12n/a Heodo
2022-01-25eOeyhnakTKJPYkzTT.dlldll ff6c8c4bf5982877d2971f9642735403087c3b871f07d18158df8fecf8a9b19en/aHeodo
2022-01-25r7zlXfjH.dlldll 681666f75c1d4a582647b085a2ad15a892aa03d88e8640b0982a9048c22be0b1n/a Heodo
2022-01-25czXNp9LpWsjQ9v0DKYg.dlldll 6c8c14f09b792b78a54e533f3a4dfa350e65fd1afb5bf3648767b82f9a942c2bn/a Heodo
2022-01-25jXnMrfneRnbFh0.dlldll 62315fbc487050406f8ecf2c6c87f75a81272b95172f3f09ba30c3821eb3a3d1n/a Heodo
2022-01-25rskb.dlldll 82aac40b6c6489aa94571db7d392de95f82bf2ffaa0ea6151b4f43ef24a5c539n/a Heodo
2022-01-25bMEvdpgROyGYRMGn.dlldll afb0160330f46961c5a087845f796266fdf844a3524b20d7d3e7e758301e6864n/a Heodo
2022-01-25iMbvzBJnRe.dlldll 94e5121124da4d59c7996411e5d6224255091d1a531831657c7b45bf7f9b028cn/aHeodo
2022-01-251MURTdpW778t9.dlldll f298db942d12d4313749c0c7e0bee89fdefc0eb2d0c3fcebcd3220eb2f4e521bn/a Heodo
2022-01-25Sny.dlldll e1f331adb8aec89d6b06bdfba95002a30f2dd092d3b93701701a709b41444c41n/a Heodo
2022-01-25o44w9HQ.dlldll f5b48f73f888b7622f261db70fd1c372e32047f08ed323f515910945ee5eac67n/a Heodo
2022-01-25Q2yok3PPtBjVeRABDAj.dlldll c5711bba861b247d816d2d8591d1d25176b7042c979fcdfb80e774152a7ce1e8n/a Heodo
2022-01-25mTEdL4h.dlldll 350fc7e3ba8f88d6e861f64b830c2600279048ebb8ed3dce2ad1a98b3fd7e08bn/a Heodo
2022-01-25hSizD.dlldll b96e2b8eb0a9e12aae0f686265358c033fe366196ef0adc9e6c2063e8fcbffc7n/a Heodo
2022-01-25S8HZrJHC7sCad0XRiJ2.dlldll f8b9e1e3fcf5a990ca421341cc7dfad0a7dfbc727cde3c0e4cb57f56e5c70080n/a Heodo
2022-01-25ORi.dlldll 9ec17407b2ec07ca4cfea9a9b05a41b8f8a72ee9f6c0bcb79c09d81214586f6bn/a Heodo