URLhaus Database

You are currently viewing the URLhaus database entry for http://formula8020.com/css/56Dzi0P/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2034755
URL: http://formula8020.com/css/56Dzi0P/
URL Status:Offline
Host: formula8020.com
Date added:2022-02-07 15:19:05 UTC
Last online:2022-02-08 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 01:50:22 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:10 hours, 33 minutes Good (down since 2022-02-08 01:53:45 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-08NFNDtKttVB9aNDVRWA.dlldll af13fc97525330c017e2a4785adff36aa66e70b3f400b540ad73e7190b8c7c2dVirustotal results 22.39%Heodo
2022-02-072KVBlQaMqUjzp.dlldll 1fb7e347b0d0e4de037f3d2b16e82d4ac598db2b4f9be37e4ac820a832d41f0en/a Heodo
2022-02-07fqpyAu7n4N0kLHF8hrO4HrPxZlh.dlldll b74d9a05c7d7aff0b3b6e2db7a64a9ce64412f3339f4950b6674cd377f6ef949n/a Heodo
2022-02-07lvEWzqyajDVgkxTrVX.dlldll 7a648f960fa86774b45cdcad30b1612c0cae2e8219a75dfce37c8a45cb06b69bn/a Heodo
2022-02-07VrIi7A.dlldll 7d60c549f8449426b471929562ca60543957dd715a6634c1d7a5f02aee453253n/a Heodo
2022-02-07p2sAc.dlldll bd98425c999645bc07a59ec905b26aca36a77d27db0b54006e45ba7af20bffd8n/aHeodo
2022-02-0768QVSb0t40c.dlldll 10a3f90b6ba16f2cf7c55fd99832a996ac17930750fa4f1280ce0f8144cd4eafn/a Heodo
2022-02-07cEzOcrV.dlldll fa752f99f8991cf36c9642eaf3606c581c2d099be3d0379e1d018e186ff350cfVirustotal results 22.39% Heodo
2022-02-07que3EdI5LXnq.dlldll 274205bfa5992956dd823d5a627edc65f58a3c350f70bdbecfc4348062ed702dn/a Heodo
2022-02-07UjQdh6bkczjRmfSlae.dlldll f374d918c3b2648e83e62cc4f73271c003aa66be0a4170e7f7d43690350c8383n/a Heodo