URLhaus Database

You are currently viewing the URLhaus database entry for https://www.preferredsupports.com/cli/rK9sG2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2023980
URL: https://www.preferredsupports.com/cli/rK9sG2/
URL Status:Offline
Host: www.preferredsupports.com
Date added:2022-02-02 10:29:06 UTC
Last online:2022-02-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-02 10:30:58 UTC to abuse{at}cloudflare[dot]com)
Takedown time:10 hours, 57 minutes Good (down since 2022-02-02 21:28:01 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-028aPKK7kxotRZr5.dlldll dffa6e34983fc33ea9568101280c2e2f6fddcdb36240cbc397616923e8519994n/a Heodo
2022-02-02I4KJhb.dlldll 1489eebf7adb912726378b08c4afcfab98506a79e2273c7c40fbc6f3fd3ed36cn/a Heodo
2022-02-02trcBOv6J5.dlldll 91b34242148e6fd055750c0be7042ef135765460bef014e70a7020248bf8312fVirustotal results 43.08% Heodo
2022-02-02PHlhd7r5z9.dlldll a0f45b19cada22bd847723e8928ec8f123b42a8cc2cca74229c3e94ed2278b12n/a Heodo
2022-02-02vaGi7GEsOdp6Dbb.dlldll 580ed8a1f491fead7403df67b773dd616ea720b1a639945c3f5040061178a74fn/a Heodo
2022-02-02zi8S.dlldll 1ba72908fe17e2366874b7284b8b4821bb6d96140d24080f7ade4d1a65ba2c09Virustotal results 42.03% Heodo
2022-02-02HslVNWnviIu.dlldll f7d3e9d816de088490d05b1bbd9d41cc71f37f6fe52bfc5ba5af9a4b81c05ca0Virustotal results 42.65% Heodo
2022-02-020ncD1NPBBCNcX3.dlldll 525c96707e6c9def2051c32ab2d7ed85a864dfe3bc553862cee3ddf57e7c47den/a Heodo
2022-02-02aAz.dlldll edd801b8f57de013d50863f50263b1851d8f2fc738ea33561dd578e09700c000Virustotal results 43.28% Heodo
2022-02-02DltKO8WHP9lcNfd0jT1.dlldll c7f3c53db9e9c075f8afd404a8954b0ca02967548fa6d315eb2163703b4361d6Virustotal results 38.81%Heodo
2022-02-02qkL3kiC4iFLnEg.dlldll 1a939451e525f790ced6e5b4d892508aea3a9c3524562e68ed85a777dbd614cbn/a Heodo
2022-02-02URpLq2qq.dlldll b435dbeca530e8ef599cc75fb9f5ba752a56379aae8526a84b3d2cd2f5403f0cn/a Heodo