URLhaus Database

You are currently viewing the URLhaus database entry for http://batumi4u.com/nwj7iw/jgiK2uwhsu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2005634
URL: http://batumi4u.com/nwj7iw/jgiK2uwhsu/
URL Status:Offline
Host: batumi4u.com
Date added:2022-01-25 17:18:13 UTC
Last online:2022-01-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-25 17:18:38 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 hour, 48 minutes Good (down since 2022-01-25 19:07:01 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-25Knyn8kYOrZmDE.dlldll 6d9b464e6aee45e011bef491d75c2915aa2c21d14444a0ab7b578a7d694024f9n/a Heodo
2022-01-250YN0xAG6PJ.dlldll 83e324174980c90b4d9afaa42055345ce5e49158a7f85eb1419e850854a57c30n/a Heodo
2022-01-25xPQO.dlldll f1973d451f0bfd20b3a612d28a673632b45f6eae16d5264537105bb31bafc659Virustotal results 21.21% Heodo
2022-01-25ZBUL6x.dlldll 55fbfbe9722c0b623035a49ab712b5171ad9d883802641bedc822bae4ae81a04Virustotal results 19.70%Heodo
2022-01-25jfXDNIn3g.dlldll a88c39e4c38155c4a25af82602fc4068d6cf24efbd9de13091ba62ef932344d3n/a Heodo
2022-01-25VDwn57Xqs4w4Eh2gjO.dlldll 080df48a397e5988896dd844e6a33726b44e6cd28849d1dc32d656cfef9630acn/a Heodo
2022-01-25gjop.dlldll 0e1bf3117b1d517c5e40a0a5651eb8d93bb4ed9188083c195c3068eb840fda7cn/a Heodo