URLhaus Database

You are currently viewing the URLhaus database entry for https://hekmat20.com/wp-includes/d6Ll9aGchU0ELA9c/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2007406
URL: https://hekmat20.com/wp-includes/d6Ll9aGchU0ELA9c/
URL Status:Offline
Host: hekmat20.com
Date added:2022-01-26 13:34:09 UTC
Last online:2022-01-26 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-26 13:38:17 UTC to abuse{at}cloudflare[dot]com)
Takedown time:8 hours, 11 minutes Good (down since 2022-01-26 21:50:00 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-26p7yDsdI9WZWf.dlldll 247bb06038a0a63d4db5573682b4b072f6e0af5916dab7646b6aa9403182bd97n/a Heodo
2022-01-26UanGk71g6.dlldll 59e6de41aec584cdc0a17c2fa12b1061921ad9a5d384fd891c6cb99092cde5edn/a Heodo
2022-01-260.dlldll bef316ca414bc6aa5934bcdf08b04439263c1eafa7a150511e4feda71c7a2932n/a Heodo
2022-01-26brWSjWr5YsBS.dlldll c18474a02d459c086649cf10b9b1edcb4da3d46642b3a51c2194c07b2e616317n/a Heodo
2022-01-26rxZA.dlldll bf79489e477c873f01f8c2dfeb314764e63da4ce7125603c8f8b392c048f19e5Virustotal results 10.61% Heodo
2022-01-26bfKmFAbr2Uni23.dlldll d5b9755d594b049f4a7ea5cb3bb3206ae05cebf34a6919969f156127c7e5294dn/a Heodo
2022-01-26NnH6RIN0bhL6.dlldll 98d22add0392c072d1caac3796646bdf22887133d06c913c926edecdfe9c531an/a Heodo
2022-01-261wbqt8L.dlldll bad4215f0bf7e8b8b5d0f333ec800d50ee1b4cb928b45572ab20f95683c8a419n/a Heodo
2022-01-26PEV8nerZosvA6fgZ.dlldll 0f340d2853e7be3f6052c610e453c1053c724dbe4fe16bf5835c843c54a14841n/a Heodo
2022-01-26DeUKDNo7BVyR.dlldll 83d597309d8a8d06c289bd3ba2ad57d659ea8fef1205e43034f188b44dfe003an/a Heodo
2022-01-26Dc393kUa2l3N.dlldll d787176ac704c8f4494c38fce1b49103ff1b26144ad742b24cc740e1f531a519n/a Heodo
2022-01-26vFltDa5.dlldll 0ca2fb6fc4830514372607278d3391288ce65a04f1b04a17cbd49ee785cb6036n/a Heodo
2022-01-265TMDRtlCtt.dlldll d8d51638ee8a461383725863e08bcedf1ba0335373b9b2d4fa670aafa703c483n/a Heodo
2022-01-26qOls3D9b.dlldll 1bb3dc7521226cb2559a2fc3cdb61d8fdb62f83ae38e9c4b2e2847ee27b24a76Virustotal results 21.21% Heodo
2022-01-26tar2C2E4BAu9Sl.dlldll c21187d2d3800f5e6d837820aa0f1f609d4e209517b1bcaa289b5acd13593d14Virustotal results 22.73% Heodo
2022-01-26dEN8ycABmhkzPD.dlldll 5eaba97399f13003f9e6d4553cecc45204b43e1971161bdfab7573a68f3f0b98n/a Heodo
2022-01-26NkR.dlldll 05fa6a493013da19cb8cd25d8c57939636a9b07594611e0a4c3d366cf08531ean/a Heodo
2022-01-26xN7URfLKANkp.dlldll f0a9aaa79fa409a874343cb132f06555c4cc0262327b6581b81dc72aa7f47bcfVirustotal results 22.22% Heodo
2022-01-26V7unL.dlldll dbb23cc1ed67cb12f22a83bfa5319c8fcb3e4d072dcb8dd3379fc22876c466fcn/a Heodo
2022-01-26Qqa2gWw10zmZ.dlldll c7b2d6c5c5ddd8cf9aeba5c9c4755492116d0835a7ddb5f121ecd4cf1c108529Virustotal results 22.39% Heodo
2022-01-26Ss.dlldll d086ab74578e068becada17e0e13088d5c97f9bea95639a3958683fb073d0dcdVirustotal results 20.90% Heodo
2022-01-26TFt64nPb.dlldll d8d53d7d87eb081413eede4ca3a8c18b5b68a198c347ea826f667689863a1c03n/aHeodo
2022-01-2695aP.dlldll 7f4a22fd46d9a770e47c3bedb2d278bc7fcb3d58365fb108c0d818d5c43455f0n/a Heodo
2022-01-26HCiww.dlldll 83de1925d8b151e4d006f58904bccee80bcd14fbb6f39b83d4d6435ec0949f78Virustotal results 18.18%Heodo
2022-01-26Ry.dlldll 605c7ce16e33317fd79eb9221733644c48b6766d23d11c89cb421d9bc87ec8fcVirustotal results 20.00% Heodo
2022-01-26S4hEp.dlldll 471915fcfc3c6858426bd52078bf36dbcb38632cc8cf695c5ab1324327c1cac0Virustotal results 19.70% Heodo
2022-01-260cjpE.dlldll d11ff5ae3667a2d5bf8038b8640db4ee787fcf3a196d0232da5d237c700e10baVirustotal results 17.91% Heodo
2022-01-26VzqJnrDj8.dlldll 5c1f30b5603c17659319abd0f9d2e2bfe17b7d783bd38142b859a3288bec5344Virustotal results 43.55% Heodo
2022-01-26wTaIPw9lLDiXXjqs.dlldll 651267816ddb045a14069f4fb0e571391a977abc291486645fa2a124a64c81ddn/a Heodo