URLhaus Database

You are currently viewing the URLhaus database entry for http://watertechservices.com/cgi/XlLR7Lj2laOu4X/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2036184
URL: http://watertechservices.com/cgi/XlLR7Lj2laOu4X/
URL Status:Offline
Host: watertechservices.com
Date added:2022-02-08 06:52:16 UTC
Last online:2022-02-18 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 06:53:16 UTC to dns{at}aplus[dot]net)
Takedown time:10 days, 14 hours, 6 minutes Bad (down since 2022-02-18 20:59:21 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09z3ZTq43JoG.dlldll 18e3b0d902f95fb74affd0f0e203b5a7d6d8a9aa17967611b17377008b5f0c52Virustotal results 16.67%Heodo
2022-02-096q357PfudsEX8IzGOU0tqD6yK2B.dlldll 4427264b03d86f921000d64ae1798301480cbe50a01bf54ce63bd846df27b6e6Virustotal results 42.65% Heodo
2022-02-09zSRHQUH.dlldll 356c789c1491159b5e7eb2e3ea35ef99c34bac1665c89bbca433482c827dc295n/a Heodo
2022-02-09GXIh4MurwFgs4.dlldll 0eb72a476714916d09916661c6fbbb7beabbd1cbf6d41f7bdb761dc2c71a4ed9n/a Heodo
2022-02-09ecjbbfb.dlldll eeb192704f32b2f938e2ea14c9c4196ed17742bcb2f2619d346d29d9c15d10c9n/a Heodo
2022-02-09VMWOaqeRGcGhGO67rDcqiASiqMBKV.dlldll 38780761a1ed393c9724835bfd6f6531fd74e06521d53b564b22f9237109c78dn/a Heodo
2022-02-09IMydvAYbw3nRc2Z8nCkSSPmKPhjr.dlldll 0494f79e858f125da2678b7ed222a332c84b02b0cefcaa8ca356fc6eb6227889Virustotal results 33.85% Heodo
2022-02-097D0D8Wiv8KnjQ4VCkF6RIGO9I3.dlldll 317623d9f0a416d4b36c823ab809ca9fd097755ca4938cbffa1e8517baee7b7bn/a Heodo
2022-02-09sR9T2GDR0xHldCrQN0Xbw5YhoxktUw3OP.dlldll 174eb858ec4e01bb163a1d5a2c7aeec491fbf92d8f54b2bdaeeded67b6c0389fn/a Heodo
2022-02-08SkLSb0sieMYVNsEUAInLogUDpEzreE.dlldll 55e044c3d30884b09e3f79042f65168ea07c360f4d4b536f875690531b0e70d0n/a Heodo
2022-02-08MJgNO1vqGbjynMKbbnTu8TtkMfGkvzNE.dlldll 3dc2049920c213731cd33fb1dc2dc5fa98762e5abf30b9f5a4b72954ce15ea1an/a Heodo
2022-02-0801pp3ZC4UdMq5ioXdTjifkkef9ktgrOb.dlldll 46dd74680b87937bf2fb189a3b71e9c172bf2fdd51ab9311159c82795f2ee4afn/a Heodo
2022-02-08iRwbTq6.dlldll 77989084fd5fdfc38da6f3d4a5d74b8283061fa44b7614933c5263be0379e399n/a Heodo
2022-02-08oIHFmYS83A04yHPS2.dlldll 567d022abef532269afc84bc0aac85d9dd963d6d3faa318fbf62f5b2a77a1096n/a Heodo
2022-02-08bbeSvcwJcIsGR9Ii2gHJVqppa.dlldll 7714c27ce67b77544e2b09d45af4866193ff529f351a93577686a59c3b253d78n/a Heodo
2022-02-08vsXePs24GD.dlldll 88973bdb48dce2f2b303a2a10e6f81ec2544aac77ea23459759fa9294f532a8an/a Heodo
2022-02-08NgiPuRUVnlko.dlldll cb8b714a2ed388acb8c5160aad58e0ee746c107537e3a7577f110994bd2d66e0n/a Heodo
2022-02-08oXhgS5EC71lq7ihucFtWWFliuiu.dlldll 7d0859c7f4f8b8f9865e5360a0789f14b9d3e35bfe2378359bee6658c77bfd93n/a Heodo
2022-02-08FMUJ83w6wSXZVNOS6gJB.dlldll 3ee4b19b5aa6a537ba6cf16438ca9b7696d1429073ab0c67fd231c917540cb9en/a Heodo
2022-02-08AZppEIRmwLFbZv6G0kqybWDbY9.dlldll 716d6128d29ca20677ecb4bb840b0a99e853e8211a3f9b9597646e2a1bd01c65n/a Heodo
2022-02-08kqN83.dlldll 659c72352e78a8973dd37b9d75aded29405c1877054bf7ef24ec4b887ebb9484n/a Heodo
2022-02-08vvN8FhUf6T79RRdrAeFFHeN.dlldll e2db96093a01703fbce113c614bef184f6e2119f9a3126cd3609e820bd957a91n/a Heodo
2022-02-08WqdZjk.dlldll c6d0aa063931ee3459b92d7a98e00db311b63febd4e18926bfcefa58894208daVirustotal results 13.64% Heodo
2022-02-08jnSDsUKA.dlldll 85c0f299931f577836498366709ac43358032e02faa2ace16aa3ef8d4a80f550Virustotal results 8.96% Heodo
2022-02-089S1kMmNF8afJCXO.dlldll eaa8c7200832626be094893063f031780e736f0cc72566083a870bfb0956a3ecn/a Heodo
2022-02-088Rzvu.dlldll d74f29e18233dd3ad0f31d06982a72ffbb53bebf5e32bb4093afacb1664d8e69n/a Heodo
2022-02-08eZasmeDx96yIAJqRkdKQw5a9ZH.dlldll 89e425ac34a8632c0310955f0643b8a48165c8795bde0c32ce189b47e00d3582n/a Heodo
2022-02-08t7l9cH2fkqXjrZ.dlldll c1ca483ce79db86247c9968a07edcbd1af2a281e2e7bf77ee6a47b6dd964f376n/a Heodo