URLhaus Database

You are currently viewing the URLhaus database entry for https://tataok.tatamotors.com/wp-includes/assets/cGWq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2034878
URL: https://tataok.tatamotors.com/wp-includes/assets/cGWq/
URL Status:Offline
Host: tataok.tatamotors.com
Date added:2022-02-07 16:32:07 UTC
Last online:2022-02-09 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 14:37:19 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 day, 22 hours, 3 minutes Poor (down since 2022-02-09 14:37:06 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09Eq0YdTTQLPIHFgK.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 1.49%Heodo
2022-02-09K2J0sAvfY.dlldll cbabd4705bbea1e95cdd57ac8793f0ca0c438713a7e900f450717ac55f441ebbn/a Heodo
2022-02-09obMKjmmq.dlldll d4b4748a0ba60e8b5070ce146ee73fa69cb1061bca9a066fc27eb8aad192027fn/a Heodo
2022-02-09ijmuyD.dlldll 7bb2d5ebb7340d6ea9b93d3d4a1447a74b0b8e4a1f64d748b65cac54f5d8bfc7n/a Heodo
2022-02-08hJJdyFccm9kOzV0.dlldll 4d89b3bfeb305ee4745b84f41ec9140351a576c242cce088dae36f7be0011519n/a Heodo
2022-02-08tPSowP6iTAUJ8yyIH.dlldll 33b3482dc3cd35da448484a48e247c83d89bdade954586bc4668c0b1ee0b0e9bn/a Heodo
2022-02-08jo6PFbYEf.dlldll 8d9d41a465f61f2cb45f92d3b1e57b66d8bab7fb7d19b681c9367eafd681962bVirustotal results 21.21% Heodo
2022-02-08U73g.dlldll dce02307c849bd2e8b186ce935db5957f1341edb4de7b17efef9569b9bb284e1n/a Heodo
2022-02-08Gxf7hCrCVro7Dnw.dlldll ff566cdbaa1b0ff19c89559668e93d160c98aa058f7c3bd8cadeee5c50c4f527n/a Heodo
2022-02-08Z6tu.dlldll 6da36a5c74c3ca79b4dce72e9d57b2144f4685bfdcf34276ec7711035c0cfac2n/a Heodo
2022-02-08BZslTEAOc6EsI3GG.dlldll 07574f84fc3f5f11536ffccb5fd0f6ff85f516793504853e78c1076c5d4a5c43n/a Heodo
2022-02-08dYBNOf.dlldll 088df1038eec926e6096fdfd929e1e4a7e70559fdc370d05122246b0b297ad36n/a Heodo
2022-02-08HyBO9jeO.dlldll ef19cab75ebdbe714e1b2f6edbf295781d704bbafd64fdd11eede26a9bb1be92n/a Heodo
2022-02-08Xz2OAI2Vh.dlldll 456c1799bfd8553307617ee800f1bfcbcd94a912acc99e175e57b2f1fd4916c1n/a Heodo
2022-02-084QsoCH2vvGHGLIy.dlldll 07fa5fc80db369239a8749adb7bfbf495e2a2cd3010b0cb91b1a92f3434326dcn/a Heodo
2022-02-08Iho003G.dlldll ef05fa5f6cbd65a1109d23c80fef9eb08d21a7b6558102b118bb79332310076cn/a Heodo
2022-02-08wSFO11uWHBlGmKB5hu.dlldll 52dcfad0624b2be104eed493ee9066835c26ea5c84d8177a14d0f38f952e9a24n/a Heodo
2022-02-08w9kPbJBNigPSY.dlldll 751078f808f0c8a1275d4ad0411a4eda6d90a08f0ad9387ded39a27091a5889bn/a Heodo
2022-02-08OgLdXCoz.dlldll bbedc1f024d4b270eef9dbb350b6cebab5825525215a66eee5d3d741a825f009n/a Heodo
2022-02-08MrhISiuTdX6kjdLmL.dlldll 178b26ca1f5d07536a7aac8636ddf86cf3f394b7e503606e73fb27fc87e5b9e7n/a Heodo
2022-02-08fK0qqCkc4YyKTN.dlldll 972e29e679afc48952a8847d15773f5571409e73745083c67d498bc6b93ce17an/a Heodo
2022-02-082VYA6UDnagGbwq6NZN.dlldll df140e5b1a73310de7dd623a849b610f1b5a6c07eee20990448c8fa24946ea54n/a Heodo
2022-02-08PZBDFTAHi.dlldll 1ce5d47a10eef52825c24066a043ec7a9f6ab919b52c8a90b6c3d44ec1a2222cVirustotal results 27.94% Heodo
2022-02-08yes1uIf9o4laDUZqj8.dlldll 8ca9858fc2c26009bbd4e2615b5b7efaa1431616065112fa204d3d1f221b394en/a Heodo
2022-02-081FDJXHMmvpEDsMDp5Fh.dlldll 44a8389edd204f22e7740446d799f0fc29cfebaef0b607d373d5a1c1e12b7f69n/a Heodo
2022-02-089L7MHVxY7fwIMvFqaY.dlldll 642a1453461c2a28e62cd2ce748badd4289bddd0a38ab56fac2ce69b4d4204e5n/a Heodo
2022-02-08JfUyrgElc.dlldll 7f3ad9e9ecc36f564f3b57fae8caaf03fd83ac0c46dab69ad12b62277fab1235n/a Heodo
2022-02-08x1qtssmVS9OSRCbxmme.dlldll 45c383bd9641646b2cffec334c0d8f88c5dbd776aa6f694604516b883c2970dcn/a Heodo
2022-02-084rJ7oDepSQZNqieJmzR.dlldll 0e3a24af56dff6c59011a1a24f2397f7e3d4830d270a7e10ddca9f741e34342bn/a Heodo
2022-02-08ZThnx12v8k9.dlldll 837b5be57c5de2613720c9df8bbe3cb6ca5e1e790e896959751209867ba416c7Virustotal results 26.09% Heodo
2022-02-08Xbw5YhoxktUw3OP8LI.dlldll a1a232ba0a59bccee99438e1bd26fc8ea119de9ee4eec623c8cffe0b5c1616b9n/a Heodo
2022-02-08g2DJk9fkAbPq7X4ZJn.dlldll 66d04681c612f5d2bfd7f9d5b3139b67792288cf8521948cc3c92c3400e72677Virustotal results 20.90%Heodo
2022-02-07xAU.dlldll fe19559b46e84e0cd321a94eb6f8626a1f5591b701409182ea44668cea99314bn/a Heodo
2022-02-07Ryi.dlldll 99f4ad017e48696692aa4383683cf2fcf01c61806c64cfe3bc8f781a52effd9cn/a Heodo
2022-02-07lyjB4.dlldll 07d6c25297d1c275a9f2d8bceede948b02da9dda8c3a307c4767be100be4ffban/a Heodo
2022-02-07wi5.dlldll bc5813bd37c5f9893898d3eec53f6774cd852a436fc9d92c67d558393259b52en/a Heodo
2022-02-07AQ4ntal9BKPD.dlldll 85082052bcdc9ee33911bb77b63aa4da6baa7fbfa1793238ed3b33ead07d7a5en/a Heodo
2022-02-07zpKReFqAupU.dlldll 309e35d125b73194af56f726665133e90da9787bf5d23c87c6b6f544afd38fbbn/a Heodo
2022-02-07geCSs977vf.dlldll c1c4f682f16bd1148ab5d46cdbfe3e8181ad1c47d6f188199c46ab7403b96b96n/a Heodo
2022-02-07RoMPx1IA.dlldll 1d9c2099d7c1f49b975ed48a1a979c0a70ea6f2273a19d13c0bf627e7064f37fVirustotal results 20.90% Heodo
2022-02-07P8GsPnSYhFesTFE.dlldll 30440c50ca1a15ad66fdffa1fcb95a68eff4169cf6792afe145a7110f352da0an/a Heodo