URLhaus Database

You are currently viewing the URLhaus database entry for http://ericandrobin.com/cgi/qRe8dRaG2HDNOOG1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2034989
URL: http://ericandrobin.com/cgi/qRe8dRaG2HDNOOG1/
URL Status:Offline
Host: ericandrobin.com
Date added:2022-02-07 18:02:06 UTC
Last online:2022-02-10 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-07 18:03:15 UTC to dns{at}aplus[dot]net)
Takedown time:2 days, 13 hours, 57 minutes Poor (down since 2022-02-10 08:00:24 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-08Lk1YBih47.dlldll c0063519fc13a46352f449c524cdff1443c1ed3b707b348e837a7c7393c5cd3aVirustotal results 27.54% Heodo
2022-02-08huAqd.dlldll f604dd992361a74e21c4ab09c42eaaae639efc196a0b981a46b3f9e1edd3c387n/a Heodo
2022-02-0831Y7o5Tq5oO9T.dlldll 94e545972116f79a856672b6095fb10a7302e1e4cb116e3d077aad976668c50en/a Heodo
2022-02-08g6fRAkmslAkewcAXO7.dlldll 2b53bd93c6de747b08bcde30ca108e7b1fffc7da0e79b47bd9273ebbe9a65e01Virustotal results 26.47% Heodo
2022-02-08NjAkqxZge.dlldll 1589a69e0803c1e34174064cff13320a0251473b490c54fbf0afacb2d2d7cde2n/a Heodo
2022-02-08pXx6vPF9IW7L.dlldll bb99ad30c5ba191f7f4d08f0f8be94907663008d309c674eea09d6061dd938bcn/a Heodo
2022-02-08nmJ1dVN.dlldll 9ddd913db1eae8af65c804299ca2888deee5c12ff568b161109c64e0066b5157n/a Heodo
2022-02-08erwZ2.dlldll 9e0ac5b17f84e95e8547004ff9f443d0058558f8c9847a171df3a08610c4cd52Virustotal results 20.90% Heodo
2022-02-070WVjX9SGyrlF8aX.dlldll 755122e1cc3ea0212eee26e56bb49f47e342e709eadad6e8f72bc081559cd9ecn/a Heodo
2022-02-079lwRLcV.dlldll 24547ec495ba199143bb4bb623cdd5d11a46f9d6e34d63af1cd409035adb7925n/a Heodo
2022-02-07ALjCNjdr8AkKQD9G8.dlldll 1c6cdb647fbe8a3b2646b4e68d0ab11666cf897f4d34b112878aa0d254eddcdan/a Heodo
2022-02-073pXZgunh6T.dlldll 09764b757b19721fd1f109f69d89d8d81196ed87a45002da13cceb3c54950c31n/a Heodo
2022-02-07T2RZJBrX0u.dlldll 7b5ff54c96dce122db6f975e01f704c79c336d942ab37b73f556b0a5119d1913n/a Heodo
2022-02-07YRi17BI6.dlldll ac30d134519a4508fff5b23c1c86b7f48bd265cd9aa4e6d98f968d8ce25d5529n/a Heodo
2022-02-07m86edZ724B5rQzKPD3.dlldll 0e1c5235590969d09feb071840436170166694a88bf596c1517e43326de9e5c0n/a Heodo