URLhaus Database

You are currently viewing the URLhaus database entry for https://lambayeque.apiperu.net.pe/assets/whnYzDBLH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2012150
URL: https://lambayeque.apiperu.net.pe/assets/whnYzDBLH/
URL Status:Offline
Host: lambayeque.apiperu.net.pe
Date added:2022-01-28 17:25:12 UTC
Last online:2022-01-28 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-28 17:28:57 UTC to abuse{at}misticom[dot]com)
Takedown time:3 hours, 49 minutes Good (down since 2022-01-28 21:18:47 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-28c92RGaVmDzWB.dlldll ae0119440d52c8118336b98765a5676c09f70ad2d998901deb7ec9258b9a0651n/a Heodo
2022-01-28HrW.dlldll 8f4651af9dc486037bdad11a44daef7abb2d50e6612374ff230515f2edbe5c76n/a Heodo
2022-01-28ADPmFdRO.dlldll 22a0eb3519650fa50df2e6d6121fce73e7ebce9c307bfa24f83f06a8c97c1a5bn/a Heodo
2022-01-28ADBDDgFNEa6pqhn.dlldll 0dec5c6f813becb4ec10183e785e72c2632d65ff755d379ea7c93c50b57125d4Virustotal results 14.06% Heodo
2022-01-28GZQx1hqGe.dlldll 847b243951ce13bba5d2958049e8485f36f907814d10f71dcfc1030a1b47d983n/a Heodo
2022-01-28krEyCgV6KM2B.dlldll fb89d421a68c7178c19e843b3e385203ca1649f576c90823d8a82b11f17152b5n/a Heodo
2022-01-28EmIctSS3Q.dlldll f7f4fca018e4f672cebabcbe89590995751742ed06cb69a9cc25fcc860f90486n/a Heodo
2022-01-284Kr.dlldll 9e6a54c91894e3dcfb0300c3e535bccf6b1e1a0dc8f78172e4b3c1af64159dben/a Heodo
2022-01-28u0Eum8od2pxe.dlldll 94f5023ee4cb29c44972e7fcf35c35b34efd4c97504a71c5b9ff37286d231729n/a Heodo
2022-01-28msGQRDQp.dlldll b48bac764ca82330d7fea2721b672104cc9a9376be7143f1381de3f562e98aean/a Heodo
2022-01-28gA.dlldll b2f46d8c97e363a81c03f9d24be31a9181e4f6605bf681a520196b552ffd90ebn/aHeodo
2022-01-28DpI1O.dlldll 63a08c9d3b0014c4bb74dc30fca8d92a0f951f6561e9edb5312b4115856fc630n/a Heodo
2022-01-28sdrdX0LJlxD5ltR.dlldll 6d2957738b887e57e124ec63b20874f0afbb4fa61b05f83a0627616607e46061n/a Heodo
2022-01-28K0m.dlldll 7a9bff4a433f6618a9d18b42a976ef9a7aa6c94555170415736630fe5009f514Virustotal results 14.71%Heodo
2022-01-284JOyCm5iANa.dlldll ba060c0e4a56008ac56c5eb7470ca7d1ac9d7ba7f72e14094dfd137191bf63f8n/a Heodo
2022-01-28VETqbWweRflf0HVxVq.dlldll 0af6c079ba9fa966b825f5b0e3ac174ff03fadcc8745373c05c344f34e76f610n/a Heodo