URLhaus Database

You are currently viewing the URLhaus database entry for http://xn--90agbba9adnzt3i.com/ALFA_DATA/ucCbi6G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2029121
URL: http://xn--90agbba9adnzt3i.com/ALFA_DATA/ucCbi6G/
URL Status:Offline
Host: мебельтренд.com
Date added:2022-02-04 18:15:16 UTC
Last online:2022-02-05 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-04 18:17:33 UTC to abuse{at}timeweb[dot]ru)
Takedown time:18 hours, 17 minutes Good (down since 2022-02-05 12:35:11 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-05WPjQdvdf.dlldll 0e5f0905a896b782e167e05d4ffba787c805bcc2fae2f6355bf921b806cd640en/a Heodo
2022-02-05UrkFM.dlldll f72fbb5bfe071e4078a86395a20142dd14a10be5ea2a7c2cf1554c9e2176e053n/a Heodo
2022-02-05Q7JU.dlldll 4bac8f2a5a6bb67e58a0c727ffb65b81810f1b7e288e9da9b7ef7b0d2fe8210an/a Heodo
2022-02-05Z25rzCaZy.dlldll b0d336f69b5e3d9372dc8e65b8eab197dc8c038e5a09a8dcb9c5c0538358aa01n/a Heodo
2022-02-059b3lPftt9Fdwgeu.dlldll 32e90a760e4a2b902267ccd58e76c6846f97e07e9937972d5c7a10ebf4fbca68n/a Heodo
2022-02-05oyk.dlldll a66013d2337e1b0947b83223eb3160c2582771df8deb86aea1291bb0aee46db4n/a Heodo
2022-02-05hXU9zsS3zM.dlldll 2baba48502480e863e671543a08bec3d60bae3d544ae32ee12af73203a9a276fn/a Heodo
2022-02-05L7cRcLpAB39rK.dlldll d03b43d7b342a20217250af8a499f08c0bcd441d81630c4631e261db7b826bd0n/a Heodo
2022-02-05ahmVi5Gv5JhZY.dlldll eed9550d75abdf145a48ea83de05aaca50d9dc57efef654209e45248168383d4n/a Heodo
2022-02-05P4fUUMO.dlldll 8a19c6e692a4db38fb1b76a0c003b86f98d978c93c79645e086e866946b36b67n/a Heodo
2022-02-05vjg5V.dlldll a633232cd5a452a65d05db1dcfdb47ed21a4231f53858c253f4c7907df1a3dd8Virustotal results 42.19% Heodo
2022-02-0576pbSe3FSwpuVXNrV.dlldll 7b15d75eeb617c61d9ae95080636e309d3c11e67f4fbc880365546933e7a6a5an/a Heodo
2022-02-05QKWcFNIcdEmDkMx.dlldll 9e8d9ccb4d4ae567c25275461af2c1dda52aa0ccf79a5b222ccc1a1385cf9864Virustotal results 43.08% Heodo
2022-02-05NyBS9ZMaj.dlldll 4f4697874f6ead98a10ee9d21adda5f99cf708c08e68f7608f05ee9275b73edfVirustotal results 37.50% Heodo
2022-02-05v8DJV2mDe0svG.dlldll dcb0e295e58edde1d2db51fcfa6c77f11510acb5a36e457eba2c1a9916580efbVirustotal results 40.00% Heodo
2022-02-05QWexjmN7CR.dlldll e97beb680b61be92c1ca9dd9cdd9a4fb52bd4fb59f9aae4311d571bf75eef2c7Virustotal results 38.46%Heodo
2022-02-04dHz1NwFnrJ.dlldll db238b6b2c13981a522bade18b5ebc3ec7182c27d5939b626ef41cdd28e09694n/a Heodo
2022-02-04qz7Sydyo23hnn85S7w.dlldll 5a8dbe44236f9f5492de4948554f38c3d8ac7da26d035fa8edcd9d160e6fb44an/a Heodo
2022-02-04rocgcGTmc69AN0o.dlldll 4eb783d7a2966b0d46f53fe0f67beda17d9996f5d3e04e8152df99b160b74fc0Virustotal results 36.92% Heodo
2022-02-04bJ3iMtRdjjV3L.dlldll b7ac0420a14370e1d44a15b7c87044afd8b80c39bc2e65ed4c08ce0217fc7b6an/a Heodo
2022-02-04wzH.dlldll b1d2508ad344661295e0aa67a3d67d37041f2256efbfe536192e0f2c9c29f828Virustotal results 36.51% Heodo
2022-02-049h5YyUG0vFpqp.dlldll 51ca1f4e65be2602a6464d24cabbd3c1b316f35de65b2eb6f676e6b3e0f9a492Virustotal results 36.51% Heodo
2022-02-04VvIM006jWF.dlldll ce9a7bb10afa685e2f05a7aebf1503752d410cd00a762230a04a886dfc7ccd2en/a Heodo