URLhaus Database

You are currently viewing the URLhaus database entry for http://bawelnianka.cfolks.pl/wp-content/Ttv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2010284
URL: http://bawelnianka.cfolks.pl/wp-content/Ttv/
URL Status:Offline
Host: bawelnianka.cfolks.pl
Date added:2022-01-27 21:43:07 UTC
Last online:2022-01-28 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-27 21:44:48 UTC to abuse{at}cyberfolks[dot]pl)
Takedown time:10 hours, 26 minutes Good (down since 2022-01-28 08:11:35 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-28FbObApMYGhJ4HGMW.dlldll 8f33360a2d65e5c13bedc49b949d6ac54c7ab2c737099b0966e8e0e03d9fcbban/a Heodo
2022-01-28D.dlldll 680c6841e584032f7d1e3d9d8d69e3aee8d54889faecff877f71083e82c50e21n/a Heodo
2022-01-282RtB1Ngsq.dlldll 82b85de24b67b5471b2edff228dc2d6c70ea7ebb56a0b8bd3520d8af5f00779bn/a Heodo
2022-01-28XHm7ljzLZ.dlldll 0060df4e81590b0841b63bf382b20037670e9322acc5400e506de4ce9b91f6f9n/a Heodo
2022-01-28G1a9EFDsqojS5pBwj.dlldll dd3ed5a4b8a9b35924e5503c105648415aa077c72f3ca40fdbbf53e9ddba0944n/a Heodo
2022-01-28ZEREXV.dlldll ed60948f48e7ea3025d33561ec4b39b6bde721eab7835601df26506604d44c9fn/a Heodo
2022-01-28qK1.dlldll 0d4e7ba5c07e3cf995627f5a0d0df3e1504e58f209d598668843293d54b21b8cn/a Heodo
2022-01-28tpniTdP31.dlldll ba1fc614f4727cbb7b840420aa596e7225cac9327e9bdb355162015039e67913n/a Heodo
2022-01-28nVgf2N.dlldll 130bb1f576d9ee2d77fd5ad6d2812c98ba10d4bfb5f7d447dc5de6dc5a3cf542n/a Heodo
2022-01-28ZWTtlsu8YdM3o.dlldll cee5992a28c49440a030f078c95f134cc57551c6898a2cf480fad74358ba64e7n/a Heodo
2022-01-28YNMbZN.dlldll 30c002b51770bd57dd6320e79b243f83f75d3da2c9b42e2a4dd19883a62f2f18n/a Heodo
2022-01-28lsMMZXh5O.dlldll 68ac7e103d23be96ec716b654ba6ecfa0037005da60324048bb90286bae7068fn/a Heodo
2022-01-28YBDns7wLhpdpRFa.dlldll 8179ecf3fc7664a03c59e8c243228eec4b47b70a639a6d85885790e4acde29c7n/a Heodo
2022-01-28UJkY0gggahgv6FFKPF.dlldll c90e4c6ecd18553487ddac6d7486ce2da5a1c82542903401733253f1653e2fcan/a Heodo
2022-01-28wOGQEjX.dlldll ed5c37e235300d950778d54787d0b9c702e17c6ecd1459f0ad4582c460eedbafn/a Heodo
2022-01-283asMD6qWozwKWulg.dlldll 79bced7ab073fd064c9b4d78a84bb00753e23b553efd8eb5d421c7ddc5016fa9n/a Heodo
2022-01-28sT8.dlldll 87dca6b2acc54dc09676cca146e4f29120f9f31b64c6334facfc0e3c1de3cc9bn/a Heodo
2022-01-289dvJFlFsLVrMUTo.dlldll fb9b06d8f681751c8e5b473872d90d5b487c2883ae9807263d7205910473834bn/a Heodo
2022-01-28qFWHqst0DQ0NgL.dlldll 6059a6908811bb2072d49e1e56a5e378016b6a3edeaebfefe37df4a06b8fb332n/a Heodo
2022-01-28dkyK.dlldll 4f5ec64d5356c3400fcdca6dcba60a78bf088d943b9b1ffeac6cef7c72f79adan/a Heodo
2022-01-28SCMVd7B.dlldll b8906f4029896d052791b2e4894c43d48c920e57c8e3d0afbcba061551b3c50an/a Heodo
2022-01-28gg1Sn6.dlldll ed1f83cd0c5d23d8fd689ce80e50112dacc1bf894d66479b7a3e5020b90ffe97n/a Heodo
2022-01-28Q48Cz.dlldll 660bbf6145a8122c451674d35e7398b11e06cbe40424f83e81dd2385107fba24n/a Heodo
2022-01-28WyFjwS4Eg64K58Z2BM.dlldll 71a244a413414a3cca22836b4d0c66a2d1c90ffff7371a7c8d0b017c8852e078n/a Heodo
2022-01-287VQjj.dlldll 1031731ba6475a58d5ebb28c045b9508596d6cc6523088f8343ecb486cd010d1n/a Heodo
2022-01-28jZrH6.dlldll ac376b1f52ec848ff839cde209ce46ba9e74c83eff68ea7dd7ac72cf1123937dn/a Heodo
2022-01-28Nl25VL5cl5yN.dlldll 88a35f8590430fbd4d7d48c25580f697540aabdd6667de5b4f74b9ab0a456502n/a Heodo
2022-01-2855S.dlldll 3220faf9e1ab736cc2da6e626876124430a59101104559dc720e6657ceb3d44fn/a Heodo
2022-01-28bt.dlldll 8c113dd7c8b43819029353004ec02af0b55ee7a1be62ac008dabaff7c8fe090cn/aHeodo
2022-01-27uOV3gKF5.dlldll 66438271d842367b161ca18377408c795642a05c667077b630190a16832ebf36Virustotal results 28.99% Heodo
2022-01-272.dlldll c978a25ee3b2af408ab96f0cf1ca853f82d3acbef5bc7b1fd8210bae3a871d71Virustotal results 25.00% Heodo
2022-01-27csFUrViP.dlldll 02aa04b4c825a73cf483444055c6b803b6d29ada086634e8d72d7a3e3410b537n/a Heodo
2022-01-27Ida.dlldll e2977123e243c39c96bb072c27954a6f212bbdd6fbac3d449f15f07c2da2d1fbn/a Heodo
2022-01-278QRYK.dlldll 69978a855026806c1287450c5b3af4502118f22a6e5f83bee0f7c14463c6f974n/aHeodo
2022-01-27g2p.dlldll 436c0e187817a8c482e5d278c38e20dd0309880e1648eecdf68ed22d272f953cVirustotal results 26.09% Heodo
2022-01-27wWuxJHMRvszs.dlldll 0075dc718772bfe8159540ba856a85f1bfc3f998c3395c39a7fab92e8a6738d4n/a Heodo
2022-01-274BC3Vr4sY9RjK.dlldll daef7434df9063146f644c2e6703fe87f8e997790bc984d88e1708e34c82d7a7n/a Heodo
2022-01-27hMR5QnpziN.dlldll 808d2bf4c868f356add7125abc92d9ce06ea88f042a1e1d91d977488b2bf493cn/a Heodo