URLhaus Database

You are currently viewing the URLhaus database entry for http://it-o.biz/bitrix/xoDdDe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2011097
URL: http://it-o.biz/bitrix/xoDdDe/
URL Status:Offline
Host: it-o.biz
Date added:2022-01-28 07:12:08 UTC
Last online:2022-01-28 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-28 07:13:17 UTC to abuse{at}jino[dot]ru)
Takedown time:3 hours, 0 minutes Good (down since 2022-01-28 10:14:07 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-28TncliOhBQUIVUONk.dlldll ca049effc11312effea2ff2a58f1d36e3eabcd449f8f6e7f383fd62d90647b1an/a Heodo
2022-01-2805xcG4csV.dlldll abb01490f754e5ae9da5c556192a20f57aba67214aeee03100d2ccc12b0e3c0cn/a Heodo
2022-01-28Wlh1I2E8E.dlldll 04da37888ba3058ffbc1f151d82f56f4be0a0aefbbc3ce3fc01f030baf6f3775n/a Heodo
2022-01-286EvNgvPQMubsh.dlldll 99d9dad78d07bea24f55b2e56f401002ed3feae087b83f0d5c55c16746a74e22n/a Heodo
2022-01-288ftOX99bDRBN4.dlldll 30464b6cde8b821d5f27e2277bd455ad6064e425229505fb0b7048c9263ffc0bVirustotal results 25.00% Heodo
2022-01-280PtsSmllmk4jHPYWg.dlldll a2c04168cd07c27cec5796c8a9743e5b8527757b95f9f6b6ecf31605fae9ec30n/aHeodo
2022-01-28nnFhuTHu02fde7iY.dlldll 90d0bbbc3e9ec498168623f621baf907bf135aea1b56669f967fe20a48300880Virustotal results 19.12%Heodo
2022-01-28518VzQasKV7.dlldll 6d576374e541b89df151c433c3cba3b262d87e5e9aa94a24822c52e293e5c74dn/a Heodo
2022-01-28z3au78C.dlldll 8233e8a78395671ae9f2908872df4d48be852c99a15cc5d51ad6c47f3073c594n/a Heodo
2022-01-285t2Ze0n3jxwXXw.dlldll d3dbad4336ab87c31d6d2e4b3ab7df8542c451181f66801b0f2b8d0703f0e0a2Virustotal results 17.91% Heodo
2022-01-28W56KCRNymWEEZQJ.dlldll ff4d9490607a9a02524948d2f980836cc2076773bfc7104335968d574dadbed6n/a Heodo
2022-01-28Ktv3GafSwhhtSZS1TX.dlldll f743be36116dc2bc251424db4670ec3b75355823ee77066f67d44cd2b0c433b9n/a Heodo