URLhaus Database

You are currently viewing the URLhaus database entry for http://lupus.ktcatl.com/wp-content/uCccWJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2026492
URL: http://lupus.ktcatl.com/wp-content/uCccWJ/
URL Status:Offline
Host: lupus.ktcatl.com
Date added:2022-02-03 14:07:09 UTC
Last online:2022-03-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003897838 created on 2022-02-03 14:08:06 UTC)
Takedown time:1 month, 10 days, 1 hours, 34 minutes Bad (down since 2022-03-15 15:42:31 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-13n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2022-02-04Fg3FlDDecNwqF1VZdi.dlldll f392b08552f5127593a8cf7f01920598904eaca3ab5c9f3a8f64259133a4211cVirustotal results 43.08% Heodo
2022-02-0417TwfUqcQSG.dlldll e2050c61c88fb48bdc15c5d51623c6e6e77b880a4177582c12b531a8e5aa0568n/a Heodo
2022-02-04kVEuKtRNRPD.dlldll 8dee684a47ac894eec85deecbb62a78e0e288e2880da282626349c2713c06ed1n/a Heodo
2022-02-04l9k8DoIKB86d91.dlldll 1f04ad422845521eef9af8e2f588366756890a91bdac604cac03a8ad689f8f2dn/a Heodo
2022-02-04hjOR5aTqnSdDKHs.dlldll bcaaf171c8a1e1f55a03caa305f7860599da533216aaa9a1139d582d567f5c49Virustotal results 35.94% Heodo
2022-02-04HSwmSoV15.dlldll ccb5a197d152ae34aa623ec2a50c307ec96b99c78a87bbccb5f4356544d06735Virustotal results 38.46%Heodo
2022-02-04svv.dlldll b2c0a3fda3c5285ca4ce2ed88b118ba70006d1aa9f18104b9e3ce953eb30a915n/a Heodo
2022-02-04C4yV1UzUE5z20yoU3.dlldll b299c0767a45e3a836f485d5a832e721c30f40027c411ec6dac863ed9e1bca77Virustotal results 36.36% Heodo
2022-02-04FYsElttCw7OROu8ksVX.dlldll 775c7efbaa9aaaca6379f66b2a5c2b47beae3c71daca89553211e9e7b9d36922n/a Heodo
2022-02-04uNQbVMm.dlldll 15bb64789364bde151f385afcb25657b6a468d2b626821a1b2d085be9f0e07bbVirustotal results 36.92% Heodo
2022-02-04NIfatgeFXnxpt3ryR.dlldll 8cbd8ddfcaa4359babffa0439df3f4dee18ab9e8da8447c6d68f95471b9e76fcVirustotal results 36.36% Heodo
2022-02-048ysaPwDY0D4OcGi6.dlldll 39deebcc490bf00c10b6402f7da245298ca1c88dcacf296d0a323453b6f905d0Virustotal results 33.85% Heodo
2022-02-04MF34M.dlldll 89ddf3ba06fa601cb7c7eaffd286d9319fa7b203c8a0b21dd448de3226738fdcVirustotal results 35.94% Heodo
2022-02-04I3qcuEM2N2B2n21.dlldll b2026f5dab4e1cfa8547301396742cd2bd5c959493fd960f9a2e4a260f15540fVirustotal results 33.85% Heodo
2022-02-04JOcbb8Mwl460ZFgON.dlldll bb059893317e55de4050b26def080ace291c5350f0802d8ce56ac8e433baa044Virustotal results 36.92% Heodo
2022-02-04A7lhEQ.dlldll feb6cb770492cb3f486709e20ed496bff88a4e5a209aec41ec45fdd0ab3371f1Virustotal results 33.85% Heodo
2022-02-045jEq9Q3j.dlldll 00c7fbda45c92b47d9f8c0cdb94c42090c413a0063f5a9bddefc216cbeeb07d3Virustotal results 28.12% Heodo
2022-02-04vE2JjeZK.dlldll bbf56b7045e0a841247ab107c33b88c0f1e22b4b4be53980bafa01e4efd017a9n/aHeodo
2022-02-0366A2tEJ5pk9z.dlldll 574334fd0c85ec760a0a260cd328235341d5b300b3362bc15f97795ecb27fc0an/a Heodo
2022-02-03xTCqd.dlldll b5259c4c38156eaf6a1dd1bd0c6ab0990113e2bad1f592dc493391661be29fd8n/a Heodo
2022-02-03g4lhd6YjgiQbAQSzN5.dlldll cea91a8eaaf2a7d7a1a6efc4b1f1ed64251638bc5491f602a34886adba7e2d4fn/a Heodo
2022-02-03DiZytf.dlldll 13794a91284d37775f41d481558526fe9bac177c621217441e485d5f743feb5fn/a Heodo
2022-02-03sTT9f6zFRn.dlldll 46585d26849c69a8d806670cfac7e349e16d589d21954703e81d321f3e2e3b08n/a Heodo
2022-02-03TJL3EUIP8JesjJ4Sas9.dlldll 1f251074bf084d7e407730ded44d56ac34bbdd60e199acd1ebafd6ce5b99aeb9n/a Heodo
2022-02-03197OsnZO2RA6A67b8.dlldll 1d15710c0c9e86084a0e4f128ea28ce63a9149f4e6397bdee687d748d490e0b9Virustotal results 19.35% Heodo
2022-02-03aFE.dlldll 4b2d70beaee3df090995397f5da9438b231564294a9f2d367f1bbe177f324cc3n/a Heodo
2022-02-03Nrj.dlldll 6d210950f36962248205b701bde950bf6b3de7c4d4053dcf3cdaa73c318e5c56n/a Heodo
2022-02-03ReJ9SXsh8QQi.dlldll a9b666beafe00af635603824fd84defc36282fea95bf82d2fab31f39036f41d1n/a Heodo
2022-02-03y2Bs5cf7zr10PKaHoL2.dlldll c68ba57b50280fdab915fd320cae43375637744c43ea10fac5d0a015a5a0f2f5n/a Heodo