URLhaus Database

You are currently viewing the URLhaus database entry for http://veluxcounterapi.orbitalwaves.it/assets/WW9KfK84odoSl7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2021900
URL: http://veluxcounterapi.orbitalwaves.it/assets/WW9KfK84odoSl7/
URL Status:Offline
Host: veluxcounterapi.orbitalwaves.it
Date added:2022-02-01 18:35:16 UTC
Last online:2022-02-02 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-01 18:42:40 UTC to abuse{at}digitalocean[dot]com)
Takedown time:19 hours, 35 minutes Good (down since 2022-02-02 14:18:38 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-02jm26rrtZmChOIiLwe.dlldll 7759a0a788a2dbbd3d2ade30612f5ce8e132da4ec75f5ddb25203a6c64ed1d63Virustotal results 38.24% Heodo
2022-02-02IB7ZyJVI6AebTe.dlldll c1886d2de341a568fc0b4fe1aca4ae19fd131bd4cc3c32213f0ede2c2172c401n/a Heodo
2022-02-02LMzl2SMpgqYio3dqH.dlldll 3202f838aff872d448a379be70d9c4e5743e6d355bae8bfdbe023b066689f6f5n/a Heodo
2022-02-02DyeCR2.dlldll c794c15f98b858f7e385e51b21406b36c62eb6cf1668a93779b05b7e34ca1d0dn/a Heodo
2022-02-02b06AnhNyuS52G5JJg.dlldll 34dc37b0f0018624d8776c4a7eb389ffcbcf25b45569d2df82e543c8a776595dVirustotal results 31.34% Heodo
2022-02-02A3j.dlldll af5480aba2d5ce9024f63e80bad95441ab9082f2503f8c6ced5048c85e8da89dVirustotal results 23.53% Heodo
2022-02-02PeTlpGtuIbN.dlldll 71c358332c790701fe8ce857d22847702f05fe57f59c677b0ef52d443d3453aeVirustotal results 13.24% Heodo
2022-02-02OQLwSkGZQ3FolTwSue.dlldll 7c5a7f13a5fb1c68f6170de98d9d92dcab3238142978f8caeebc750b5a1202a3Virustotal results 16.18% Heodo
2022-02-02avCacM5cjKiBa.dlldll 6362d2adbf1ba662397ab67cb0c92e3e132928606a8c9865828c7878e441bdd5Virustotal results 13.24% Heodo
2022-02-02JTRBR5nL9ohPOx.dlldll 7424f3a6c1e04809201f0597ce905d7739cc844a8d4e232fb6fed76cf89f7937Virustotal results 11.76% Heodo
2022-02-02xcMrPQPIgSh2icc.dlldll 2edebf47c147c1f43a8bb8ad7f37cff98dce95c7f1f8f72fec4b7ad669ef28c8n/a Heodo
2022-02-02Etq2lRR.dlldll 0266e40ea7c8f9bbbe936d7ad170eca967877de316d3e8f4683e2c04d60cf558Virustotal results 10.29% Heodo
2022-02-02ap.dlldll 48b120e5fb55bf16b8ef128ac993c52838a50af6f691e0f84cd39164e3ff8331n/a Heodo
2022-02-02CdLLLhd9qX6kk.dlldll e25bcfee59f91ee60facdc9d6be0ed386db2a9bed31ee6dea3ebcdcc53838d33n/a Heodo
2022-02-02ikY8hSLw.dlldll 4f8887b7ce4824c406ce659068ed9aafb05c1d2cfaaf6f96e21056a7cb790a52Virustotal results 8.96% Heodo
2022-02-01eW15bR6YPqWYFrKHl.dlldll 8eea78a3a5a7419c93117e8dc38eb643a1f8f5ee633d1cafad310ec5c9286b94n/a Heodo
2022-02-01ckRh5.dlldll bd4eb8558491467139df69731e614132c445555887307d88db294869dbd077e3n/a Heodo
2022-02-013bkLl8qXgnIOtzDw.dlldll 75921ebd256378a24b05dbd850e9534b576efabbaf77de73f15c49ea0814918cn/aHeodo
2022-02-01VZe29aq9bg4pko.dlldll a338ff263d22a3b0933afe88f4ff9855e167b4857322ccf157c546c7d55f43c2n/a Heodo
2022-02-018GAJogURMI8Ottd.dlldll 911f46799c382e934dc2fe4b8a78e28168b37c14b52b30e041aac54e6c1fac80Virustotal results 7.46% Heodo
2022-02-01LTX.dlldll 68abf80c19353657d24c48f505056420dc61a7f320bcdcfdaf02cd8bcb9b9ed9n/a Heodo
2022-02-01Z7HUWUEHq6ul.dlldll c38b5437aa9dfefb0ceb0b1344d057970963002eb6ed9768f4e3b5a3b3c23bben/a Heodo