URLhaus Database

You are currently viewing the URLhaus database entry for https://forma-fit.com:443/images/Xf8aUlUw2q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2007517
URL: https://forma-fit.com:443/images/Xf8aUlUw2q/
URL Status:Offline
Host: forma-fit.com
Date added:2022-01-26 15:06:10 UTC
Last online:2022-01-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-26 15:10:19 UTC to cloud-abuse{at}yandex-team[dot]ru)
Takedown time:3 days, 18 hours, 29 minutes Bad (down since 2022-01-30 09:40:00 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-264JMjZDowo2yxWCV.dlldll 268f5e4b066f55e8c8f920b68ac1092fef1bac7e80822991043acc7f2d5fd2den/a Heodo
2022-01-26bcdfaGwuR9hLqImi.dlldll 09c271a3ef1700e78393cf018bcc67748708e28953909a67ed392eab2239a1ean/a Heodo
2022-01-26KcxC0VGq.dlldll 2c98c890c05224e5fd564e39a7f89d36162a9213fbc66c51abbd6670a1e274den/a Heodo
2022-01-26kf4q.dlldll bfbc00f444368e5cc387d35c4b644b46cb8799e5e62462ff391b57be7443e9e4n/a Heodo
2022-01-26U3iiXqh.dlldll d9b6ff3896fca4e08660e1ce2204edfd45ecf80bf8efcb36dafa80eeb60d9687n/a Heodo
2022-01-26Zwd.dlldll 6f4ee8116150781131847b3e1a6755d696b3a6845692139c3a6ed92e4d21a9efn/aHeodo
2022-01-26BGzBqw.dlldll dba98b9fd0294ab850f998081a39cc55e41d1a51eedf3f6fedc9601c1363d26dn/aHeodo
2022-01-26KFGFIZ.dlldll 2fb5650debf0e8678b1898db9265722f7e395c212bd9af92ff2ed5c3c991b242n/a Heodo
2022-01-26qy8PvRNY8ESfBPSe.dlldll cfdb5f6101a7efd98bc0080a91b652756b8d677a5166e8e180d57f1e1fe1dc44Virustotal results 38.81%Heodo
2022-01-26w1vqRnhbmmpg1Ss10m.dlldll 325f13f984b977e8bb7fba4f78d3ed0feae624fdb5a030aee9f98824efb4f3a1n/a Heodo
2022-01-26yqN.dlldll 8ae90ed39dff1f672b6706765a8bbb236d79a461df6ee781a30ce019114751d6n/a Heodo
2022-01-26m5NyYwtv7yMqKi7YvQl.dlldll db65d0dc7f3b355cc1385b1675abdb8df4c4b2699abee38de209e7fe0efde300n/a Heodo
2022-01-26AwLCXIZD.dlldll 07ac2ba6fdc6551cdcbac89524d746874c766864f216a6ebd4093a3d7242d4e0n/aHeodo
2022-01-26uYLU60Oz4JcZsN.dlldll 12a3429fd1cf1927208edab8d3cf4a734c7200a600d336b37c84e79d807a5204n/a Heodo
2022-01-267ZH.dlldll b1e2dc193423cdd934f999592a4b13b2f7eeb3327f859348d202219b3c882a64Virustotal results 34.33% Heodo
2022-01-26rMncZrctxaV4efG.dlldll a7b4dd5fb64f4b2d4d3e79120ae75907a7c6dd976f1fddbb16efa21b27996cben/a Heodo
2022-01-26SBgxjtl2U.dlldll 975d20f8cda7e472e35b0c9daadae664126cd7f352cb343fab6489488e9f17b2n/a Heodo