URLhaus Database

You are currently viewing the URLhaus database entry for http://lissbernardin.com/hthjb3i/x9KHpCeYrr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2034756
URL: http://lissbernardin.com/hthjb3i/x9KHpCeYrr/
URL Status:Offline
Host: lissbernardin.com
Date added:2022-02-07 15:19:06 UTC
Last online:2022-02-08 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-07 15:20:23 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 1 hours, 54 minutes Poor (down since 2022-02-08 17:14:54 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-08udaoVtMzl.dlldll 3832a217c193bfdf4e8d424920950ed7dad9647949e5c3bfd1eaeb0dcc83073en/a Heodo
2022-02-08qOAtEVA5ZWMB3QTJlEA9IzwWeUnyH55u.dlldll 6cdb01311fa4fca25876603648ca2e2576ef8949b42855258861b40e2cfade00n/a Heodo
2022-02-08OpbGc.dlldll 1d19f1af3e7e375efe9b033ccf1075d503d0d30c290c02f20a15088cdd352adan/a Heodo
2022-02-08uJQJ456.dlldll a686d98a43476d4a200d3039864f77ced8fea7158fdde2224de060b22bf7fc8cn/a Heodo
2022-02-08rKkcFHvtPXjk4sqf2E.dlldll 75dca4a79406c7dbbe63a956c59a1e078086f1d7d85c99e01e7b2442feea46d9n/a Heodo
2022-02-08SWwIcgaC5ByDDKqW3ljee4z.dlldll d3729c585b0842eebffc0d95220f96c812464daac83e0cef545e1cb78f827204n/a Heodo
2022-02-08TzFvRfLCuTZYrUJfD41J0.dlldll 08a8db7e78cfa856c1898b1e97ff1e4b5bb020daaa6fb76244af520779e6be38n/a Heodo
2022-02-08z7kVapXEsVp.dlldll 5c725716c7f0b64339d7adb8ad5f2e22efd5c4ec41a7d9e57123644f19062f3en/a Heodo
2022-02-08vC0C2SmmQavMClY2gMD0CIWc.dlldll e99cee32b3df4fba6bac488785d148dbbc12dddbf03cd59cc117405d79caeff7n/a Heodo
2022-02-08SzzjnY2Knng5yHkUdEIJR7J.dlldll 2a1b4ab783e7a3494a028590674d47e93a7f204a7bb7f98a6f5ee10cc91aca5cn/a Heodo
2022-02-08sEvZfx7pWtBLfqvU8IJMl7FF1tl.dlldll 0e6fb3b7b47a85600cf8edd8532e4878e78f9f1c8f36df2c5a708264b79cbc5fn/a Heodo
2022-02-08FCVbZ5yr7VAyOShBTN.dlldll f38a25c85463881b91e2dca578857bd4974c8693bd526ee42ce047889288ce9an/a Heodo
2022-02-08PvceRWsbISeuavI9.dlldll e52d4db6c3e0b70c92454a36b06200077c0f26fee73b46597c8082af0fb3534dn/a Heodo
2022-02-086Qm9R9IPaoT0828MlRqZqpnFPcP.dlldll f9e443c8821fff4bcc08b05343601b8ef3fe969accbf6eda0f18050c70442ebcn/a Heodo
2022-02-08HmOfZMWrUIFFMBov97B.dlldll a330e57c89acb0a5ef1cf0e910026002fe2ed50d52dc4711c21c5cb7cf3c0a93n/a Heodo
2022-02-08oBjLCqR29vyMnCnJt.dlldll e17ff76c07aa11f9f328770d01334cbd9b0130b3d9c3d49ebb94edb41e3dac0cn/a Heodo
2022-02-08UI3D6.dlldll 28c187a728429d5372e673c9df81cb4f17fa41ab886d5bf0575f0af05f93f559n/a Heodo
2022-02-08BFppDfKFRRYIksg.dlldll e5f4d08c2ff55ba9b60ac65b239801481a6e13d3991b45fac7613c39ce290df0n/a Heodo
2022-02-08mjCzEhUsOnSbor6HlAGlEpLB.dlldll d35963ff2b7bf1daeea5315f825f028ad7993791d3fa8af42094890ef6d03d02n/a Heodo
2022-02-07Oyak29QMyDOmH.dlldll d5b1fc5336c492875ad60df6179d4651c3d4acb6772d349f6a9454447588a052Virustotal results 22.39% Heodo
2022-02-0752a3Q2hGM.dlldll 52f71c342e1e7be56c5173534488f89fbc4fbf5cf9e8e22262bf5387776fc6e5n/a Heodo
2022-02-07nLtjYpmd55xoINUFsvrZXy.dlldll cf91c84c4820de55f851e074a8f1389701d15ad8faf862a68a255ffd60521a53Virustotal results 21.88% Heodo
2022-02-07G5C6uoZmcxJOlhVVV.dlldll 7a8632981a5fcafafaeac5d3848423424183037c11d0747f4a99bd49a6f5521cn/a Heodo
2022-02-07hzRQ0.dlldll 1e928fe7dda483f6ad39deb813cab1b492292fcf3bf07b5fff99f516dec9cbf7Virustotal results 16.67% Heodo
2022-02-07b52gXli.dlldll 09c2944cca75af62b52c42903cb14dac96758635f1cd43d688f60cc9b089cf85n/aHeodo
2022-02-079.dlldll ebb539c56bb0809ef4aa4ea74e8b6f9fb91f0dcb950a88c948fd34f8e7fcdb7bVirustotal results 23.88% Heodo
2022-02-07nk1nowii.dlldll 5a66ae22194f827597d22b271e042be4832b7f2a2b6f5f3104254092d14609abn/aHeodo
2022-02-07Eg3hbrRWZSpWCq68T.dlldll c7910ed43996672718bc0bbac16dc1bf3d97723a55837cace7c4083c8fe7fba3n/a Heodo
2022-02-07WEBUVVG.dlldll 53448d0d93c45ec130513d74ba0c9c1f320244deb74a0f8ae0744d18dab5e75en/a Heodo