URLhaus Database

You are currently viewing the URLhaus database entry for https://savagerefinisherinc.com/cgi-bin/Ny1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2023984
URL: https://savagerefinisherinc.com/cgi-bin/Ny1/
URL Status:Offline
Host: savagerefinisherinc.com
Date added:2022-02-02 10:29:07 UTC
Last online:2022-02-07 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-02 10:31:03 UTC to abuse{at}hostgator[dot]com)
Takedown time:5 days, 2 hours, 39 minutes Bad (down since 2022-02-07 13:10:20 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-04dnK.dlldll ed5cc4c4878fb3433c853b6129232a6dd8da5eded42eba915e8c52ac0c201e7en/a Heodo
2022-02-04u0vTDdohOLmfIUayf.dlldll cb8c02a39a7ea5d5977797599019e61a69cfa0a9d941a9ca1741f4baaf191fefn/a Heodo
2022-02-04mwuf2.dlldll 58778203aed3dcc22724e2e5e9e441dcadfb335413d8600d4063f879680c5284n/a Heodo
2022-02-04zZvvEsjE6.dlldll 41d3f08c5bf41131abcb6775d4c260d210ed784570be6f2110a80f28119498f5n/a Heodo
2022-02-047Uekp3FCxxUrQHF.dlldll 3e61b6a8e09df57ea07a3450d54526a7c657d02dcd56ddb165f9eb30f82356dbn/a Heodo
2022-02-04FFmrnO.dlldll aa55d17bc87daf50c6b24c4af89c8e9858473ad045494561f826361c66cf129cn/a Heodo
2022-02-0485T.dlldll 3c74bb1f38aa4dd82a9cd71aea06454e0d54d4d7c2f7dd7b48611e0c6410af3en/a Heodo
2022-02-04ASk7v.dlldll 4177de6295a4535c2e94a15574e2b32205f076d692e85bdb1b2254dc98377962n/a Heodo
2022-02-04OUf.dlldll e038da2c0dc8daf654b4078b729174414bda259f4ff7f6cbf939905262da2b6bVirustotal results 32.81% Heodo
2022-02-04m1IoWXyNtU.dlldll ceb2494c0e0b1a20e1c90be62d95d0eba37950296b151949353f074443794647Virustotal results 33.85% Heodo
2022-02-035hdJ1JcBm7ao.dlldll 76f1e82017130e8a93429498ececfaf4c759ca574fc16c7b0a82f6b146d0576fn/a Heodo
2022-02-03ISSOgDXXZPvkQ.dlldll 8189a136fdaadae91c8d158aa43ec965e013cb93780a8c091d20adf9295171a7n/a Heodo
2022-02-03De29CTT8ecmBYeB.dlldll 649d205aa52b32cfa9dd3114700cd316ed244a280fdeb7c8a70650cfe570e9acn/a Heodo
2022-02-03QC37EDegbMfdSrGl.dlldll 0c62ce9b594be92749c5258085d5895e5e4c0d5451ca3731920c2fee4d2bad97n/a Heodo
2022-02-033h74hgKPX7i4J.dlldll a8755aacfe16a54be1c6b61738ccded86f343df709a0daa94e405e42f502d843n/a Heodo
2022-02-03M4zt.dlldll 932d81448fa9be9f3251c0da0b7ad70a557c67428d90d3de05c85b3c22e1ff6bn/a Heodo
2022-02-03VNOK8s.dlldll d2f75d1af8bfd2e31ae6944a6d22ef23217e21a0b9d08996b144f9db4546bde5n/a Heodo
2022-02-03k44ni.dlldll 7651d28fa77a28f9953314b2bf025ad30f0178810b01954733fad12ff0ca53ecn/a Heodo
2022-02-03hTz.dlldll 34cca503087811060c6acf2a328b0ab38927ba8dfd673362cdd59946a8cd5e15n/a Heodo
2022-02-03tip16mzCT.dlldll bfb049810776e73cbc5e7fe9f893700c893b5aa901579f3ecf1ec10fb3cd1186n/a Heodo
2022-02-03xK7.dlldll def259951c1b7bd68fa046cfff68909f8de03cf74056a7008d000b169f875821n/a Heodo
2022-02-03YtPGvBrclp.dlldll e7df3cabc95cf780cb6fb2527485b4eab4e35e4746ee420e9d7f3af37feba079Virustotal results 41.27% 
2022-02-03iUZU61.dlldll 00880090e213623a7bd316afe2f2d4159fef4342ec70b5a3919358eda85c198en/a Heodo
2022-02-03gEg0dHVYjT.dlldll 66ecbc620503e8c48ac685b201e4d2d85c3126c7d983e055dfe6aac6a78edf38n/a Heodo
2022-02-03uPFY8ALA1l.dlldll 029d3152dbddf75deb177100517356a10b21cbb5c57747c0bc8bf3250ce7cb94Virustotal results 42.37% Heodo
2022-02-038kbHwuz1ubQWXBOl.dlldll 69cb01cc8858ad01e3925d43cc4b4c0e8b53d54c3c5c231d8ea03a90dc36f4c0n/a Heodo
2022-02-038VSvFl1BOk.dlldll 6305ee2c69b3de27d0ce7a40a6335dee8d0f455a948d2953493e0efddc59d296n/a Heodo
2022-02-03nd77vIJn7UP12j75.dlldll 81254a70bdb3202551fc53cfbaecc791aa88cf9d9ac2339932fa47cbe8e35ce4n/a Heodo
2022-02-03smk.dlldll 1bc42148735ad8253abf92b013aad25756adeaf11d486806a68af10cf5c5975bn/a 
2022-02-03icCm7FbMq.dlldll 8dd0d65a8afca62fb0cd5c0a95717ad175c508cddd196d12dafc328ccac822b0n/a Heodo
2022-02-033sNG.dlldll 62b9cbbdfa154dbcad92bce08481726f816f89032b6fa7fd0d3a80a66d568526n/a Heodo
2022-02-033ND9hqw6.dlldll bc9f1ea3018898fa6bb49bbb200026a800706c6ba4988de981879e18d2d13becn/a Heodo
2022-02-03XjV.dlldll 55212fa31c86911d45aa4d271d3c6ea7cd673ddaeaae73e072aceaf0d4ebb4ffn/a 
2022-02-03vQYB6tYcE9hJBet.dlldll 3393fd6d1df2ca3127204a5a26a44e839fd7aee63121d7d5ac49a181d5a6d4dcn/a Heodo
2022-02-03ASbNT5WIa.dlldll 76400c29a002c92dafc7a2ab27b32bacabd7b2790c8f28bacfcc7fc69bb0c949n/a Heodo
2022-02-03O07D0.dlldll bed707a169b6c7f73df6e2fdf82d0de1a21b91e0561fde0c99fe4d03abde57b1n/a Heodo
2022-02-03FXLLOGCq.dlldll 2777ebc54c2ba50d7cfa04f05f16b8cefe5f6d15a2ab2e61eb0189fe9fc2bec5n/a Heodo
2022-02-038llnUqiB.dlldll 0cd23d6770a74b9fa0ab3597acf824f5fcad12487b177a3fb01dc76edb587537n/a Heodo
2022-02-03eLub7LQbC8.dlldll 3f7e502c95e004cd272de4a3062460e12a6cfbd5483c20f2fd4c30eab2e52188n/a Heodo
2022-02-03KyyOdoBIh.dlldll 43cca4d9edfde3c7bf632ecccd4ce95323ed5e702bbf8ea45cd3e964507b0f6bn/a Heodo
2022-02-02MoU9jc7Vn6ZZzGDr.dlldll f2a1bc2fc0ca995285c910ed5690cc257a63d0cde3be714a9de1fc84d39fad4fn/a Heodo
2022-02-02GTdYqTiXXRgg2yzy0p.dlldll ca63c45c4203aec7900ccb26cbc234cbe85dd07189ab823b171377649e517603Virustotal results 28.36% Heodo
2022-02-02xVjHuT422AwPIeAj.dlldll 0fcdfd25194a54e76d88f9df049af4103a46ad6fcc0978b8d0b18afea5a06788Virustotal results 26.15% Heodo
2022-02-02D5WQoYx.dlldll 3464e53a65e5db00c28276502b448ca7a96e150ccd3d09df2dcb892128b3c07an/a Heodo
2022-02-029JHGFgiRM.dlldll 1fec3c8d22d9b4c86d4e17ccfa14e5f74768aa50d55a10242e0c996ec1492556n/a Heodo
2022-02-02xWonetthLNGPMrW4.dlldll 39a60ed63f672ac7ca71c798f37c53105a7d6d60bf261b55f9c7e11b0fb926c2Virustotal results 42.65% Heodo
2022-02-02pzUmaArYIhdscwVSiHE.dlldll 4d903adc2cb6ac5314a57298a4c0df842e3e0a616a6cab020e02d720a9fd1aa8Virustotal results 42.65% Heodo
2022-02-02BIgXiPgpS.dlldll 9f1a356033d1091e960f7df0859a2a1c390159f9541dd9dd23d4d1dab16614e4n/a Heodo
2022-02-022nzW05uw5y7Zi7kG8.dlldll 5e98bc6a7b8a1261b18c8a80642ba769e08a6e6d84c613a1f4e1e75990230677Virustotal results 46.38% Heodo
2022-02-02agQPvVSMe88uPaMX5.dlldll 14b64bfef7e96e70a5027ab8aa688f9df665b65c083d2910eef3edc14c9917dan/a Heodo
2022-02-02lE67ld.dlldll c5aa4b7f9d17f4b4b359fe5e3de782db4aba17023cc6c22fc9b7e1693b0c039fn/a Heodo
2022-02-027B194BzBFqp.dlldll c28d788800ec0ab0e72b256bd179557aebf50316ba9f647787934f10b2e37f5cn/a Heodo
2022-02-02thVA.dlldll 6c61c322425a1698180f60ca55f51b2c603e550a198ca2940c0449bec4d3529dn/a Heodo
2022-02-02MyBtdrK1.dlldll 9f50907b4e91fd2d168a8921facc8223d47fb27c2612783f2d4ab3d83d29b60bVirustotal results 39.71%Heodo
2022-02-02Coygg5GnOz6zxx8.dlldll bb7b90b3b49459eba5cff75910f4455ded4aabc95c7f6fa48f0c1af8c570f43bn/a Heodo
2022-02-02hf2hj.dlldll 51249d3e49f75843913765a1bfee949e8a40aae3aecd9d3ff0ad85c029622c7cn/a Heodo