URLhaus Database

You are currently viewing the URLhaus database entry for https://glowrentals.com/wp-admin/dXzQO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2033794
URL: https://glowrentals.com/wp-admin/dXzQO/
URL Status:Offline
Host: glowrentals.com
Date added:2022-02-07 10:26:08 UTC
Last online:2022-02-07 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-07 10:33:45 UTC to abuse{at}godaddy[dot]com)
Takedown time:7 hours, 42 minutes Good (down since 2022-02-07 18:16:33 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-0787wCsP.dlldll f35fd40c33c0a89a6aad526780cc9840d1cf40c1bbc08f232d41bb15852cff02n/a Heodo
2022-02-07WZKXzJNvTsWxr83S.dlldll 479a3a731b5cdaf347e02f9c290e9fab0da1b033adb2bbb443bcae9f75a327c0Virustotal results 22.39% Heodo
2022-02-07DssZw.dlldll 88924c02185c83daeb864a32bceccd4e3905cc7a6edb023ee7bf7e0bb1290142n/a Heodo
2022-02-07oTueeSG.dlldll 572fc3dbe6fa8d086b77c141a51400b9e89578ab526f4105f784decb9ff91325n/a Heodo
2022-02-07BzO79nLChmnelCNkk.dlldll 2493b8ed94ea1254fe82ab82cef1a66f515a91c63164a62d03922b3b6b6bc3fcVirustotal results 20.90%Heodo
2022-02-07TfFyr7ocqCi.dlldll af4124a7676e17f5b40a33fdc484b600f52d2f22d4aa50b725c1e2a9e497bf79n/a Heodo
2022-02-07slQ.dlldll dd44c1bc538ee31b0c7336864f6d905b1921a5d430376309a4c4fd4d51b67fe8Virustotal results 41.18% Heodo
2022-02-07Xxt17XbPgUkNnGBBF.dlldll 1b8e4b8feba28a23842d2356d0c37d973a9037f25083811ffc96ef1c5391c110n/a Heodo