URLhaus Database

You are currently viewing the URLhaus database entry for http://varafood.com/Ajax/cnM91G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2026612
URL: http://varafood.com/Ajax/cnM91G/
URL Status:Offline
Host: varafood.com
Date added:2022-02-03 15:17:15 UTC
Last online:2022-02-04 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-03 15:18:25 UTC to admin{at}internetnamesforbusiness[dot]com)
Takedown time:20 hours, 3 minutes Good (down since 2022-02-04 11:21:54 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-042CR.dlldll b6e4ec2f6af9d3e80425457387f75a230bcfe3f2b679e7bca34aa56eca495b5en/a Heodo
2022-02-0486XGx894bK19bunQ9.dlldll d7741152b7695ca0dc171760c37c6f153bd8d03605fa4f6d5cb1713e6dc7c53eVirustotal results 29.69% Heodo
2022-02-04cvVz2TJd.dlldll cf2c296bafcad1373c95a712990b56f60d1f3716bed64814f5b419dfbd5bfdd5n/aHeodo
2022-02-04lL30m2I15ZbvY.dlldll 735f71dac15dacd2b0947695c6fa5b09c9448959020d0ed9c96e085b4a8e6ea6Virustotal results 40.00% Heodo
2022-02-04kJwkYu8.dlldll 3e2252d87ff00393c5442b0f00635a34cf03e60217a34393feb86e37024c8932Virustotal results 38.46% Heodo
2022-02-04rndr3810uwgl6rF.dlldll 80408ba28594234ce87be7bc96c207abb2c895e1a93dc821e11c8d14ece4de2fVirustotal results 38.10% Heodo
2022-02-0409jbB.dlldll ef01dfbdc7e4b05214861d51bc248258d155ad57bb0eaf26cee4fb1afd039ee3Virustotal results 42.11% Heodo
2022-02-04Ae2lOMeCAR.dlldll 1ba3e38cb967737b73538573344e0a1c5909adcbeef0cefb4f358e60ff5d8326Virustotal results 36.92% Heodo
2022-02-04qa434JxbT.dlldll 613a465619f13655aec688d2282b337331a9220c03800384525c67a03a7debd9Virustotal results 36.92% Heodo
2022-02-044rrtkJJqs.dlldll d0f3554794d5a3a72864cc26cb76f9a5d4188e078048d1633ad990dd8d400e26n/a Heodo
2022-02-04nBW3zQbPsmB03gRc.dlldll 781598858e0776ded411d11b53e7909d8f02b992b0aeb037d9566f83944fade8Virustotal results 30.77% Heodo
2022-02-046SHEDKtgbEXe.dlldll c6d0ccc829388ac841a8a8f5cc722ceb2a6fd7d3fc34d485b057b3664e66a5d3Virustotal results 35.38% Heodo
2022-02-04ReaeZsHTblp4YU.dlldll 96d98cd42fe86bd413df9f918edd05bd22f27d7ddcc169ff59ce8d3daa8df5e8Virustotal results 35.38% Heodo
2022-02-048bgP2soBlq07Yual16.dlldll 45e1eff418e056d444fbc14f86e1430afe2e0ad92577284e779b805f111216adn/a Heodo
2022-02-03gIXIjUWaHFqgGeutFF.dlldll 74472f4ae96cce6e18e124e8cad5891fc178225211078de3afc23e304a6feb43n/a Heodo
2022-02-03EIIg.dlldll 299418de8af469bbbf799108275190173268734e138d8478804ded54995999a5n/a Heodo
2022-02-030VRAk.dlldll 903d0a55211723dd075194ae095f5c5cba048b0da1659b53b9cb0510c50b7978n/a Heodo
2022-02-03vp7qGNKpSXr11.dlldll e4bee2ca0a16414038ba4ab0ffda87907600d8eba4ae2275b535dbb2cb799e32n/a Heodo
2022-02-03MzjNTKpiNABBIr.dlldll 8e20e8efbaba910231583c794bfd6dfeabadfc3a9a746ec67af7f68c21bfeefdVirustotal results 29.03% Heodo
2022-02-03PP.dlldll 1d2329790d5c3f9bbd9206432a0061eb5ff5215988c98dad269656c25486cc8fn/a Heodo
2022-02-03BF.dlldll f3cd1b382555c6998b3081cd16b23612dca759ad8ca4af8cea2ea79fad121079n/a Heodo
2022-02-03XLsTWMYiMkh8HOP.dlldll b4e13c70bf270d42f31e8045a4424defe90b6e3376a7835c1e4f96e8fae8adebn/a Heodo
2022-02-03SolxxNehugHQvS.dlldll 5447cccfdec8d02098ab8621579eb6f3e26c83730fbf2c1826611ee6b8c427e0n/a Heodo
2022-02-03sJhi5B5FPaDUBT0.dlldll 391a0d2412355cf0c5da0af88297b1c96942af33d1739f73c6a8e917a049bad9n/a Heodo