URLhaus Database

You are currently viewing the URLhaus database entry for https://biz.merlin.ua/wp-admin/W6agtFSRZGt371dV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2024714
URL: https://biz.merlin.ua/wp-admin/W6agtFSRZGt371dV/
URL Status:Offline
Host: biz.merlin.ua
Date added:2022-02-02 18:03:18 UTC
Last online:2022-02-07 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-02 18:10:26 UTC to abuse{at}merlin[dot]ua)
Takedown time:4 days, 21 hours, 36 minutes Bad (down since 2022-02-07 15:46:33 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-04aD5.dlldll c2ddc1c90a97bb08464c46cfed30c2cedd5d63b27eb8d69b0ada3826f18db4fen/aHeodo
2022-02-046G.dlldll cc40e17f448434134a0fbf4b0f9ca384b57bdd3ea62d9b7d8f06bef0ab9ae054Virustotal results 37.50% Heodo
2022-02-04zM.dlldll 2f76e83aaba889a0ecc5720fd01e52b48f9fcac4291c198ad9be606ed28b4eaaVirustotal results 40.00% Heodo
2022-02-04W6DCU2GblkPu.dlldll 0c398043505e19713549ccfbd531d697ec6a079f773cac3a2cec8b122c449b2en/a Heodo
2022-02-04N0Z.dlldll 5a23beb80d982c36cf3c4edbc910861ac4e89bd780dedb43f514d1fa6b4d3d5eVirustotal results 35.09% Heodo
2022-02-04ywqTPIYCkrOfGg7w5.dlldll bc3a40819a082ef8c45916aa0d44e1ef470fbefa3d290eda0161145f532e1945Virustotal results 32.81% 
2022-02-04kOvTTjJgG6Kkc26.dlldll b642ab1d497792dd61a2751578e62a37ede3b3d79ae386370704703276c8bb80n/a Heodo
2022-02-041umfmGgM5xlv.dlldll a6a4a692cc5e655a249a4f3c7c0d1dadddf6133db115366114ccd24d6d5e4b75Virustotal results 31.25% Heodo
2022-02-04Yws0C1pfIsgE0NlBr.dlldll 614a49856fc4f5c12f619d570dc0ffbe24a6597dd7bac1613e2ef8dbddea4fedn/a Heodo
2022-02-04TXXXA1i1NMitiC.dlldll 4e43ca1c23dad83eb3f4a430997ea0882d7334cbc4ccccdcb21c9b2134117cfeVirustotal results 30.16% Heodo
2022-02-04rythb1yg1Cm.dlldll 882e528f93fe1bd85aff1325409c772bed2a6d6a902056cff70df9cc1a0ba37aVirustotal results 28.12% Heodo
2022-02-04p7ULDzOK6176F.dlldll 61ab2a0bc39053a05f03c7535fe92392ba3113d7d67ac32860d5c0106e1148bdVirustotal results 39.06% Heodo
2022-02-04UUcYBqWbcdYyo.dlldll 3c90a4fe2df899ca26a9fd41b3cb4c4f3a52f0833968fb2b88979bf4a5e8c682Virustotal results 36.92% Heodo
2022-02-04V.dlldll 34e44e616f3a0e8b48fbf0c964d60b3dd915e81d94b6f53569f617001714dc2cVirustotal results 33.85% Heodo
2022-02-048yD8h8NpS.dlldll 0371070aeb069eb0677e245437c5ae9f5284383541adcd75c93aa71df3814b88Virustotal results 35.38% Heodo
2022-02-04HaE3WbuTxkLziB.dlldll c97b4b33c8be4a67b2f3072960aee94e0ee5a08ad425404c94723f2f80bc9377Virustotal results 34.38% Heodo
2022-02-04VOWMDmes1pNrU2zcf.dlldll 89a609198811bf3c92225255e561656f8c9b29c8a4fee4e1d3c16c179412a127Virustotal results 32.43% Heodo
2022-02-04qqYBBWY.dlldll 3a61dc8a4eeed320d280bfe98197c95fe53f45d85588a4e4fc27de604057ee18Virustotal results 32.31% Heodo
2022-02-04KoztFY66uZNv.dlldll f1dd5ac5fa3a71b02e4caa9f46547d222d6b15c9affd45d201613f9756ede472n/a Heodo
2022-02-04A.dlldll 3ff2acd5adbf1660f8d784cba6389c73f7c6868a4539a0f723370c0bf9de904cVirustotal results 33.85% Heodo
2022-02-03oWD7.dlldll 13902b523b6fe2c271e6dfb9a0a24916d1cb3497534f7c5108af38936025b1adn/a Heodo
2022-02-034aG6Z.dlldll d821d520bbbc6a6774155e6fb7e1f1a53ca0f8348af892ea83ff6e4d7f80310fn/a Heodo
2022-02-03wb7zT2MWFc.dlldll b7e1ec3466a75e8664f25aa12761706a2f4266e8c3b7a3971ba64480739fa562n/a Heodo
2022-02-03dieyf.dlldll 0761bfc7cc8598d43c44c38fefff959c5311b67f28e7dbc4c6ed079e0ab4d67bn/a Heodo
2022-02-03fJxupuh.dlldll 338451b52d56b630ae8980d1fe6f67e03802238e2e358ca8498b1c65d71f9acen/a Heodo
2022-02-03m4c1TdRQZd82z.dlldll fde079bda6f614a08b02e13d51e6626fe917df0814897b44cc8f34c91d47cc5dn/a Heodo
2022-02-03zHhXrSC44xNN.dlldll a48cece63d1358fc2aa2d15f83d5c5bde4d4d8bc27406a548d9ccbce505b07ffn/a Heodo
2022-02-03zKd.dlldll ef3692c13af5419cb3569c252401e57528cde9e714972974ea8b14269d80448bn/a Heodo
2022-02-03y4AhGXwtTWv4Q.dlldll e3b01fc8a0831f4193f1b3a11693df04178a339cdf3d23f9620ff1947ed17e0cVirustotal results 14.06% Heodo
2022-02-03JrrJc5CYnntA7rM.dlldll d8f54b64207e679da827dcebb14ee12634e0b7a2802cae2a4c8a48784e525ad2n/a Heodo
2022-02-033q.dlldll df2bedc6809a1e951ccfcf5bef01d5490747e19c4fdd23a5af51f53c72e595acn/a Heodo
2022-02-03Nxe.dlldll f119e1fe844d637e68dababb4d9d17776b500f30ffaffddc2f2a84d00e9534a7Virustotal results 28.12% Heodo
2022-02-03XuIgCzvW2Cg.dlldll f7c6267a8249e29c0814254852466005d21c076a4f96e5dc0412a12d0ebfa035Virustotal results 53.85% Heodo
2022-02-03OizzBF3.dlldll b9036c01cd33ec9c74aa8a9b17b230d34802e2b2aacf6d2fd699066c1a355a73n/a Heodo
2022-02-03vQup.dlldll d6fe202c537f35d79dbc8bc2a98b22ecad5e904362293ba04e1895d37964d094n/a Heodo
2022-02-03YYVHOto4uPdkcfkgb.dlldll f89f47b7eff089d0e67eb19edd8c8f9d11c73e0df8164def50166446098e3b49n/a Heodo
2022-02-03VGFP.dlldll 728029210323c5f7bb2a33488e75be0af4c929448dbe65fb0a38daf3a9b2c96cn/a Heodo
2022-02-03tIHiZ5OCxPv32VKL.dlldll 37ec5ce81bc55dc8952b45180e26a8e69b234f5f7be3b71b03ef3a0a7e859997n/a Heodo
2022-02-03EJTi4v6iC46c4.dlldll dff4065af4a47ca77fd5cd052d2ec66ccd8d894c9276c20c94edbaea31f7c263Virustotal results 52.31% Heodo
2022-02-03ZeJ9hNI6.dlldll 24279c7cb33a4d57129e8fe2fafb50359f29bb10daccef09d7ce83c1caaeb4f1Virustotal results 42.65% Heodo
2022-02-03sxtWge4LX.dlldll 7094fd9033109ec377cb35d4d565a1968a7d6ccf655deaaf511d940aef4f9197Virustotal results 45.59% Heodo
2022-02-03VnOBRhh8.dlldll 3ca5a3e2299656ceda1cc60eade239b967c17febdaee113c468f76f52b0e2d52Virustotal results 45.59% Heodo
2022-02-03HrbJdrB.dlldll e40a5bae551ee725dd8d97f00f75be74f849593d20bcb9d3d799aba6d78f99b6Virustotal results 42.42% Heodo
2022-02-0337XcZUrgWHvj79l.dlldll e03f0695b4ee8d11675a01d989c17c10428607891a8cd8cbc66fd554365180e3Virustotal results 34.78% Heodo
2022-02-03My0ZkT.dlldll 1952cef71f7f0124e488dfc3381d4bf949a0fa11746a31f784b1bfbe98c74cf6Virustotal results 40.58% Heodo
2022-02-03AY7MSjuyJ.dlldll 8b9ecd2c5728d844e5a19edc5a1ecca941f4a6074b2e8ef9771c55b1ddd9fb18n/a Heodo
2022-02-038K1FBrj0FuUzBTl.dlldll cd2031f1751040af2680dace0becd236234edf1fd58b47b8a7bbf755e516b240Virustotal results 33.82% Heodo
2022-02-03hhoa2xDYgLE.dlldll 4b1ad2fb3cd8d0d7c2bc47dfec2be9022e8d3edda24b282c792927912a6dac3bn/a Heodo
2022-02-03DGRdA.dlldll 7ceff8c2b6832a5ef6785b4edfbf19123a89b466cbdf0b5f6adc7a86138b8a9cn/a Heodo
2022-02-034DDail.dlldll 0dfce40d1037c91897b64fb927012bb5e575e8cd08330b6c6c46a9b0d4c87900Virustotal results 29.23% Heodo
2022-02-03sqHR4D.dlldll 209948de8b9334be8ec16d1d7249772e4a6f650b872f06885b3373c7cc4832e1n/a Heodo
2022-02-02ghrWDHUo1BBZ.dlldll 24aaa662d6139f67d63361c6a1cc64b5e56ae7813504196faa1fedb8dfdc1275n/a Heodo
2022-02-02bwkibCo96.dlldll 1d452e60c52f057e3102ef9fefb0b4fde24b87c7a6242eb6850f45c3af6dfe53n/a Heodo
2022-02-02AyDLMDdBBnYyV6.dlldll db8c1d273042f6d3b87aba02956b868ff4c6a8c020cf24c69193f910839742ddVirustotal results 25.00% Heodo
2022-02-02mCp1zkkw6UL87ZjmY.dlldll 632cc5fffc6ae6570f72a5cb44721bc0e5148d5f5c325c66581aded05b9625ddn/a Heodo
2022-02-02hGeL939RU1tkbjs.dlldll 4d166e291d329da8daab4d426dcabea35e252dd3187f0d955e4ec37c08bc9512n/a Heodo
2022-02-029RGGLXv.dlldll d3eb765aed328f01942a7f4233d83f04c22b4640b258263068fa089e9e4e9865n/a Heodo
2022-02-02VT4jTLaB53KzFY.dlldll f1832c1592d4157e4c3924163244c6d0f96c25fd67208753e04d18ba1acbbd66n/a Heodo