URLhaus Database

You are currently viewing the URLhaus database entry for https://onewaymedia.ro/wp-includes/k/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2009442
URL: https://onewaymedia.ro/wp-includes/k/
URL Status:Offline
Host: onewaymedia.ro
Date added:2022-01-27 13:46:09 UTC
Last online:2022-01-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-27 13:52:45 UTC to abuse{at}rcs-rds[dot]ro)
Takedown time:4 hours, 59 minutes Good (down since 2022-01-27 18:52:44 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-27WoGaz8F0jeLPwkh.dlldll 7963febfc0946f73a6760100ffe7076ad0621a1e29406089b74d43ee87414a05n/a Heodo
2022-01-27iQy2Gy5F1BYEtuL61.dlldll bfbe89bcb44d6ce2e1acb596a61e21bfc22c1181800628a94e60a13ad30020e8Virustotal results 22.39% Heodo
2022-01-2780mSCUcy2yx.dlldll 0de2c3d101301581841e2294ae23bf514ee078fa6466c4ae880175d7ac40d20aVirustotal results 20.00% Heodo
2022-01-2776xYcr0OcXa.dlldll d6d2af902f588f8bb6515181a3c9508b2a0b2431c936d101e81913880730beabn/a Heodo
2022-01-27PyT78tCuy255I4.dlldll 7e1323a558a693adb08760540ba08389682432ca9e6f707fb47f9e26ab17769aVirustotal results 21.21% Heodo
2022-01-27oH6pc.dlldll bd0b18a92ba26df0c8719a1d0ac77e72a1eb6305adde690757d4860298e7fbe2n/a Heodo
2022-01-27xERHh.dlldll 2aace1af1042980e4882eac06230828356b43c3176e9e79c681890b354ea73ban/a Heodo
2022-01-27pGlyRkgn.dlldll 661b5d662d374a9e0d17b390927c3a812408f0a57e06e32169dab9f87abdd5b8n/a Heodo
2022-01-270dFk.dlldll 3537f43c34627edf5a5fcf4ac577360147b6a27c214ae0fa7d39fae33034a24fVirustotal results 21.88% Heodo
2022-01-277x5FHTsZL.dlldll a51113cf9b46c841fb917f9925898bb6c7e874818951472fcb176317e0454cb1Virustotal results 22.39% Heodo
2022-01-27ca7OFSD.dlldll ff85965640b1a7cad70db4ca2b49ca2f562044604e28665c00dcdea8b0fd8e9bVirustotal results 20.31%Heodo
2022-01-27WLM4TfPFrnDrJRe.dlldll c23779bf046e119f080b3e73230411ef990a0788a398eff02fdd2a278e9bba33n/a Heodo
2022-01-27vjKLp63FdxbZrySR.dlldll c845b1c5a43cad878b64b0c6f37eb10cc2aa41ae5fb365eff7ba728a085f6854n/a Heodo
2022-01-27TL.dlldll 0731f3ccc3cb257f04898e9c8ed73b6b63d16d8dbbc94143ad8ae3ddfcc10571n/aHeodo
2022-01-27310DZ5dYi.dlldll 9b9e2f5210c0036b37e4aa010076498cb8f353c7c3fed6ae28b1c13024411af7n/a Heodo
2022-01-27ZAwZV7Nxytypccy0r.dlldll fc1c5ad4863448f70757dbb0b6abf4a569913581ceac24fcd24eb64eea268ef6n/a Heodo
2022-01-276fQCUjm2JkT.dlldll 3fc38d0497e05db78c6f22773a6e668a6a6a4828e4ead73d13c0b9e8a44cb595n/a Heodo