URLhaus Database

You are currently viewing the URLhaus database entry for http://lynsmithgroup.com/hftm2i2/KZIFwjmwWI1sy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2010294
URL: http://lynsmithgroup.com/hftm2i2/KZIFwjmwWI1sy/
URL Status:Offline
Host: lynsmithgroup.com
Date added:2022-01-27 21:43:10 UTC
Last online:2022-01-28 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-27 21:44:57 UTC to abuse{at}godaddy[dot]com)
Takedown time:3 hours, 39 minutes Good (down since 2022-01-28 01:24:41 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-282DrW8lPB1WerML.dlldll c57a4ac221c1c7066a9372da0631417c6dec20d9269a54593134b31924638896Virustotal results 30.43% Heodo
2022-01-28AD38qZ7x7jj.dlldll 1e7a70e5e582c9a6274029251059f0f2fe1198c94dc207d9a302c017ea839863Virustotal results 26.87% Heodo
2022-01-28eQLakig1LexO.dlldll 175e17cf6eca7c7dfe44f8b4a54fde78cf883837a32367429c08ebd71fe8b2ebn/a Heodo
2022-01-28VeZHWB0.dlldll 30761d484482c6fa27adb09eeb76bb9130d585e6e42a44b1a1a037395342e232Virustotal results 28.99%Heodo
2022-01-28OpxsNV6TBPR.dlldll 5978b1b3372d7e7ae5de96c7c6764d9e8b5960424ed82743814711f822d42f89Virustotal results 27.69% Heodo
2022-01-27XL1bOUP.dlldll 2428d24aed13ddb29c6d73fdfaa233a9c76dbef1a6aad493ed6e2659fdba200aVirustotal results 30.88% Heodo
2022-01-27RnzYn0lQ568weR.dlldll b032569907cfaf929eb66e9ce1a0fb658b97d878178871d744380521dee28c00n/a Heodo
2022-01-27oSbSI.dlldll 3b898781e428627fea4e55af972db582c0f510527d417d9d58d3548cf109593dn/a Heodo
2022-01-27bbagZy.dlldll 108d3cb4ae9cdee17d1ba0461c508330701155a62d3e3f887f6c13cf5d752b6dVirustotal results 29.41%Heodo
2022-01-27PbeyQHpxFZ.dlldll a7325d214ceb0a951e5f2a691b91b55d186e21b5918651461e72ac6a038f136an/a Heodo
2022-01-27UvgC9YJjyjHW2h.dlldll fbd34aaaf63755dd237f726230005ceebb6687b4bb38eddc513d2c39b2ec00d9n/a Heodo
2022-01-27hw5PWwp.dlldll f684e0456f7140d8c27af6ecb746aebf01c3cdae11dc9cfbd55da570d3c4180en/a Heodo
2022-01-27a2U4cpQ4GklC24.dlldll 61819982e4c08c905bce8e6eba8f6eb6b49404a1a31fecb28e9bd478407a326an/a Heodo