URLhaus Database

You are currently viewing the URLhaus database entry for https://gfnl.org/wp-content/rwdBTLqAfNSYW3L/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2024474
URL: https://gfnl.org/wp-content/rwdBTLqAfNSYW3L/
URL Status:Offline
Host: gfnl.org
Date added:2022-02-02 15:34:06 UTC
Last online:2022-02-03 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-02 15:35:20 UTC to abuse{at}limestonenetworks[dot]com)
Takedown time:19 hours, 31 minutes Good (down since 2022-02-03 11:07:04 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-03u58nWx.dlldll 557314c94ee8533af1b6228c8813a1990faf8db4d753ccc55eeeeb3a979fadb5n/a Heodo
2022-02-03qHziwNnnvcvBT.dlldll 2d17e53eed5c35944ada497e35415e860dd00a8d948e0bae8ececd94da90f77bVirustotal results 50.77% Heodo
2022-02-03z.dlldll ff6580cf4b0e251fd19f8c378f08af73bcccc54d00bc8f2cd6220e0b87b3cd1dVirustotal results 52.31% Heodo
2022-02-03kDGIzHEmFHnwu.dlldll 5941b56da5c2dcabf3c0587772c8cde7a6123d45a91cf65c044cf48940d26378Virustotal results 50.00% Heodo
2022-02-03wwO60.dlldll 9f7b7a7ef1061e33f1869cdb4add77cfa3f18b5f8a80ca620e995ce23586c8a8Virustotal results 48.53% Heodo
2022-02-03qu.dlldll 5264a127d2bf65e2fb64fbe6e8ceda5aff7c8a450963c2cfd04d8d5b57ad7f95Virustotal results 47.76% Heodo
2022-02-03dYOlzANDgzEleelM.dlldll d17881eeff148619cd9e497433b407475a186e40f4e1b80e02b3fdc2b104345cVirustotal results 33.82% Heodo
2022-02-03Nl2b.dlldll 2fb013bc77a9d24fa9a794bba6fff5ef7641567ea76bf625219a25015696567bVirustotal results 38.46% Heodo
2022-02-0332R.dlldll fcb50bec8c90981ce119f2c3f7e41d6969d66155fe851eec1274b9269c4a9fb9n/a Heodo
2022-02-03qP2fwvnbEwyf.dlldll 98ada8e5ba451662a4ddc8be92baf6cfb64a090dab9fb62e3729e6ca3736690aVirustotal results 33.82% Heodo
2022-02-03bvEgZ.dlldll 6e63ed8a2f4e9bd466d49fd4e4251b55d04133020e37ceb6ef59da667fa12f94Virustotal results 33.82% Heodo
2022-02-03MXqLAss9rePM1LMW.dlldll 4922dc98c84d8133f6a90bf9a11c3c8d4665ef33f7c82a59854ec78792693849Virustotal results 39.71% Heodo
2022-02-03NhBsKwjMLVdQhF.dlldll f47448ebced206d70d06411a3bce3700c5aff6b7d4ab8590847cf3d104b3da8bVirustotal results 33.82% Heodo
2022-02-0309CfCwb8t5ddD7I0.dlldll c8988a15b77ae5d8149a630bdf30071b6be4ab2ec3b04239af871609de1dd839n/a Heodo
2022-02-03WQfaJF1DRPtUFzu6px.dlldll 87517ae2bb8961e7ba9203dac1c2317253fbe1dfefe7fd64b8eed608d4bb0415n/a Heodo
2022-02-02JajkeVJ4.dlldll 87568b2047e7f9cb901100c949cf25cc48851b9e8ffb7d10322a406a7ac58199Virustotal results 30.43% Heodo
2022-02-02xh.dlldll cf9d942c203f7f3309cd40defb3d683ffdf34458e649292c1cb11c677ac15424Virustotal results 26.47% Heodo
2022-02-02Wxoo.dlldll 2b70b02199daca94f37b4a7c4cc17c538ff764f739b516ba0f08ef16b5fd7919Virustotal results 29.85% Heodo
2022-02-02779NMlMiaQDc.dlldll 2bbde3ccc2f1dd75bd5f77ad98a5a8449f24cb39f75fd30aca2a378c1ab01ce3Virustotal results 27.54% Heodo
2022-02-02VmQqTnJVd0qm1f.dlldll 65a4ee893baad75ec245b9c35ee5dd99c19bf0c9cfd63d821353889cfc658f4cVirustotal results 25.76% Heodo
2022-02-02J0zl1idqjew.dlldll 0804ea724e7956dec35863b0864a8e582c3c0bfdee015d7b0d30f5fede6549dfVirustotal results 23.88% Heodo
2022-02-02kIws91R5f7tE7.dlldll a002f06c2969a8240360af7b5336572c619b4442fec3cde710bfe16f6a87186fn/a Heodo
2022-02-02lAx.dlldll c4691cec3142a97ba0c6ae00d8646c9d977ed4fd57324af326f9a15d8cb2e7a9n/a Heodo
2022-02-02Mp2BVuKEArYCTT.dlldll f955b3081306fdf1a155c845559d5061fc5403a03444e59ed527736c670a5445n/aHeodo
2022-02-02FSITMZrllNnYt.dlldll 22982e6b2f7be1ecab006062baccfb516c0caf1132421458423767c809a77b9an/a Heodo