URLhaus Database

You are currently viewing the URLhaus database entry for http://zimrights.co.zw/oldsite/k0EoCWycU9tNo1d/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2026620
URL: http://zimrights.co.zw/oldsite/k0EoCWycU9tNo1d/
URL Status:Offline
Host: zimrights.co.zw
Date added:2022-02-03 15:18:18 UTC
Last online:2022-02-07 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-03 15:23:24 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:4 days, 3 hours, 49 minutes Bad (down since 2022-02-07 19:13:10 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-0568RLnqOqnrs.dlldll 45f2b258fa7586ebed93c8605e9f4ad7dee408c5260d6942f2e8c68d48945662n/aHeodo
2022-02-05h.dlldll 69a47eecf7c7c6d34a11ba65f073b99177c75e27f8a87a5e778e7bb33f324a8fn/a Heodo
2022-02-05A.dlldll 19bcff81fe994e247bceb0720e66c9385b360665a058a67fa30b833babfc2cf8n/a Heodo
2022-02-05WshmnK0yJ3DeWnN0.dlldll ee72a44f3ca3e3bc69a5350404e5eb5eb396ade6a8be17e6573dd6fff0d2a864Virustotal results 52.31% Heodo
2022-02-05eWy3xnMzcxrOwlnS.dlldll 461dc70b216a6485fe58a868d0c01a62f572c677268e48a6a2d4c7cdcaeb444en/a Heodo
2022-02-05EyCgV6KM2BsIVHRU4P.dlldll 5f380de1e950da741466aeedc61b6f906360193a559aff4e7c60a205458ad4d3Virustotal results 52.46% Heodo
2022-02-05KRvcz.dlldll dd3abe9eec0df8edaa157564aede6ca223e6469769db2d5e09195c0ef9453336Virustotal results 51.56% Heodo
2022-02-05oF5l.dlldll 03ca3d848f3eb7ca9664ac151d24e48934d230c26e3c5b18a938c66924c9e498n/a Heodo
2022-02-05VebjzMbFMJA9UMLuZg.dlldll b382e6b30efad721f72613e7bd975d17aff55bef205993cd7632d0c2c3bf1e99Virustotal results 52.31% Heodo
2022-02-055mlEoPclesSJfpv.dlldll a7757fe7708bce03ba1695c137893c17ce1e4ba9e3fdfb81bd6c9a7be3517bafVirustotal results 50.00% Heodo
2022-02-05f0dFvpehzQt74bX.dlldll 558a0598eac4a9e1642d5fb83fe161fac5a18708f3fa0d28e4006e9cdf77d496Virustotal results 46.97% Heodo
2022-02-05aYAT3Xo.dlldll 49049c8c6ae1c91ddbee493b388de13a0371e36dab91a82bedaae7d0779f3e24n/a Heodo
2022-02-05MG311w0j6.dlldll 1498f908bae96a963952bf770df047581abfa6e40daade00c76e26a32c8084d8Virustotal results 46.97% Heodo
2022-02-05K.dlldll 10e0dd0b178cd6279fa5edd66636483ce7392f66277c6da1eeb30d86f9e88c73n/a Heodo
2022-02-05W0JQhsC.dlldll 957f7b7e04a4061cdcc0545a9ffc8365a6af8bfdce345a79d4446c1c37e4fd74Virustotal results 45.45% Heodo
2022-02-05HV6LZ.dlldll 60dd2e091f57eefddebe3e5e4118a2bde76d6b2f2e72ea2ef402f206a3bd56ebVirustotal results 44.62% Heodo
2022-02-05SDYqjB6qT2.dlldll e67a0abd1b1d6e11948de7917960878f15230df884775b086a5a27f3d337737aVirustotal results 37.70% Heodo
2022-02-05iD9Y.dlldll 751d925830d6f1f7cddf7626333caf8c71bdf8d2acb7dc6ff004de0e8fec3b7fn/a Heodo
2022-02-05rH70QK.dlldll 62b1d8509a7d122e95f4579216b590c454a0a28af6ba8884c08cd1d93e984f61Virustotal results 40.91% Heodo
2022-02-05SC6Ec8.dlldll 93001a491a0993f76b09193bebac65e48209a9caf5516543cce703f1a46f4602n/a Heodo
2022-02-04Tp9c37W1.dlldll d69cc0a2507f0420c0cf349905caeec5ec0d1ed0f82fd7607419443b53ad58c2n/a Heodo
2022-02-04Ga5hVUUooGsb0xO.dlldll 939e2036c8bb32e8264dac789f0d37510677bf79d1dfd13ea63b9f34be11fb89Virustotal results 40.62% Heodo
2022-02-04KVJyhWbhCyhKkvOkr.dlldll aa954181c9b1c41849e5bbc7d0d03049ec1a9f9bdb8746cd56993a9152cbcd9dn/a Heodo
2022-02-044MiWWb1kIWJm3.dlldll ec28a8d6db964a8bbd8f324770b74815f50ddc7d3ae96ae42f2fb9e136a21ffaVirustotal results 37.50% Heodo
2022-02-0429HhjfE0Iuw.dlldll 1fee23b6cd5690cc37933f760b749f25d0b3a956873f76598fdaf96952c6d1efVirustotal results 37.50% Heodo
2022-02-04s8b7tKnFyjO.dlldll a57e6b207bac56a868f1738f3d073c683f0c820579c1ff5b6e73ced41347b3ben/a Heodo
2022-02-04fm.dlldll 59fc3ac6cf1316a6a45a054c839e5be202efebcab914299f24c4963cb1e7489bn/a Heodo
2022-02-043SsvY5yT5rHtN51h.dlldll 4f543444808dd21eb266e81e7857994a4aa3e9e7e039890ab8c8c81f3ddad018n/a Heodo
2022-02-04fPG6WOVE0VmFcWQ41W.dlldll f84a488ab0106c7e2d8e46cb9a25abe6704dcdc66cd244a7d23838692f99d69bn/a Heodo
2022-02-04UG5awiKFmXo.dlldll 24ba77ac9e3bdcc5cb97c550b3f70e70df8b0a9aec8881bc01d418e0ebacaaden/a Heodo
2022-02-04aqrtUCTZZe.dlldll 446d58a83d63d4e5605d3982a47c89bfb5cbd3b3495828b23f198312039d239dVirustotal results 32.31% Heodo
2022-02-04qUqGsKMIjMMFMPeUA.dlldll 4fe2c6413d73e47cd82d14f66d99d97d182bd48407cefad374ea48e2bb17f481Virustotal results 34.38% Heodo
2022-02-04VawWQ8vnNpndqwK.dlldll 4a8de5e8b626efcf9ca07c5bf06f99e0872180be72b8312eaa7229f9b90056c8Virustotal results 32.81% Heodo
2022-02-047WmHXZIIFpUM.dlldll 48e5510ac00bcb103172e4f2155f7e16be3c65f62fd40f3720608fd9810c5d77Virustotal results 31.25% Heodo
2022-02-04Vx.dlldll 9bbfceb44e482ff8c3c6c9c83da7a65988ecfa92757b20f0820fd41d9d927ad4n/a Heodo
2022-02-04sj0UKpOVKf5QvwKg.dlldll d62e30a35f96f6c1bb0027eec0080be0729b7658560f6c3ee4ca0402b39e4239n/a Heodo
2022-02-04uDqia.dlldll f2808def470ef806786fea15ffb5740b007fff123b127ccfffa0073ff648365fn/a Heodo
2022-02-0447lwgPZ1dk.dlldll 5b495529a196bb8b43dc7a0d8cde900f113f2db80addf8e9fa89d0e1c56e41aen/a Heodo
2022-02-04lXg4H91pH9fI.dlldll e2b3dae598beb6ec23afb440588d5eca495ef57ab51850ce1838ec8fba8dfc3fVirustotal results 34.85% Heodo
2022-02-04EVEzt14N3wsXJCk2qo.dlldll 1549b5b151f5ddd7dc24642668e3c7393494394c0c69a72d4f314966ddd7ac61Virustotal results 34.38% Heodo
2022-02-04q.dlldll 9ffaccb783d5bb9ad725674cc12e680b2bebb09402abbb781d7722937245252eVirustotal results 37.50% Heodo
2022-02-04F.dlldll 96bc8b6c0f81e76c981ab3e534fa9d37726e37aca25db1abb45a2155ec0440cbVirustotal results 38.46% Heodo
2022-02-04GV0im.dlldll 4a989548806eda7c0ad754427acb45b5df5db302e7941247ec1cd41942100413n/a Heodo
2022-02-0442AIdgOK.dlldll bb19cecede7dc9985d95736199d571dff51ff539e049582e9204b85d776c8c69Virustotal results 36.51% Heodo
2022-02-03mjV8.dlldll dc1c3685a24600d323ae8e89458b6a67e8cc0e41b1e82a8edfd435351c6a07dan/a Heodo
2022-02-03HS9pFttHSF.dlldll f4755eae83cc2e8b4852f9aa6c8efe63f4489b59320c9f1a369d6e461d7d59a8Virustotal results 32.81% Heodo
2022-02-03XLq6dq3c33T.dlldll b93da3eb25e9789427e87fdd1d30b1feb5baa995514ae59a4aa602ee4017a2eaVirustotal results 29.69% Heodo
2022-02-03CPnWS.dlldll 81bbabad41619427427879f05918fd434db4b525e2ee0fa0415d69137fd74aa7n/a Heodo
2022-02-03Bhv6VJAgYG6MuH.dlldll 914eaf9e29fdeee3b56ec59c8403e2144a92a59d452301cc94ffab2db892fec4Virustotal results 30.77% Heodo
2022-02-032vvf0I7ld5yVHYmlX.dlldll 47b3d4a7b4857d76e015c92de76ff2e7893c0bf655801c64d9228f2bff84a6c7n/a Heodo
2022-02-03u.dlldll 56d08776c99f104c7eac53b9d182b44caee8dc91f032d33406faf16c89b38ea6Virustotal results 19.35% Heodo
2022-02-03LHBI0sr.dlldll 8f7f91f8f7d2db8c4b429fb2616709faaff21839789c8cb8e31bc6a4e58ce433n/a Heodo
2022-02-03RGPIA8B.dlldll 7c2c696361b2d4e0c0bc37fe4924a106496d16f3b8bd0a796e7583c810318039n/a Heodo
2022-02-03gYmC.dlldll e369c32e183347ecb68e4432b6c1add4379c0a2f8f690468a766a491e6531080n/a Heodo
2022-02-03dCBdK9.dlldll 4b5083a2c66cb76c19a897c2944772096422278ecb618f22b2ac0317173d62aen/a Heodo