URLhaus Database

You are currently viewing the URLhaus database entry for https://forma-fit.com/images/Xf8aUlUw2q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2007531
URL: https://forma-fit.com/images/Xf8aUlUw2q/
URL Status:Offline
Host: forma-fit.com
Date added:2022-01-26 15:17:11 UTC
Last online:2022-01-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-26 15:22:48 UTC to cloud-abuse{at}yandex-team[dot]ru)
Takedown time:3 days, 18 hours, 21 minutes Bad (down since 2022-01-30 09:44:19 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-264JMjZDowo2yxWCV.dlldll 268f5e4b066f55e8c8f920b68ac1092fef1bac7e80822991043acc7f2d5fd2den/a Heodo
2022-01-26ltcD.dlldll abd303c5f6e5e4cb1328196631c2a6d2bcb87e0fb3403c33992bc63b33375466n/a Heodo
2022-01-26KcxC0VGq.dlldll 2c98c890c05224e5fd564e39a7f89d36162a9213fbc66c51abbd6670a1e274den/a Heodo
2022-01-26kf4q.dlldll bfbc00f444368e5cc387d35c4b644b46cb8799e5e62462ff391b57be7443e9e4n/a Heodo
2022-01-26U3iiXqh.dlldll d9b6ff3896fca4e08660e1ce2204edfd45ecf80bf8efcb36dafa80eeb60d9687n/a Heodo
2022-01-26VRCykdrhgSM2Q.dlldll 49e4a0cc2f7644b039deb973f83f1cbf6e2afe0745959ad0c314b4f81210dc33n/a Heodo
2022-01-26BGzBqw.dlldll dba98b9fd0294ab850f998081a39cc55e41d1a51eedf3f6fedc9601c1363d26dVirustotal results 41.79%Heodo
2022-01-26KFGFIZ.dlldll 2fb5650debf0e8678b1898db9265722f7e395c212bd9af92ff2ed5c3c991b242n/a Heodo
2022-01-26Q9y0vB28p.dlldll 8c7352323af5f79709047ff0593c593f9f67040b08b3ee3457e2954bcc5956ccVirustotal results 41.79% Heodo
2022-01-26w1vqRnhbmmpg1Ss10m.dlldll 325f13f984b977e8bb7fba4f78d3ed0feae624fdb5a030aee9f98824efb4f3a1n/a Heodo
2022-01-26FVcpo.dlldll fffbd64abaae4e41c5e6c4daed1b03271cecceac05bba925eca6eb2a91a91a1aVirustotal results 34.33% Heodo
2022-01-26AwLCXIZD.dlldll 07ac2ba6fdc6551cdcbac89524d746874c766864f216a6ebd4093a3d7242d4e0n/aHeodo
2022-01-26uYLU60Oz4JcZsN.dlldll 12a3429fd1cf1927208edab8d3cf4a734c7200a600d336b37c84e79d807a5204n/a Heodo
2022-01-26dNPANrwG0W3.dlldll 79379c53a13eae1848f85bbe985fbfe36f216fc425e60a120c5558e233e728b6n/aHeodo
2022-01-26zX2AJgrF24v6z0LDJb.dlldll 4bf4610de4e379f4c98a9a3a4c0bd0cc182f730d71546e145fe11c60b2ddc8d9n/a Heodo