URLhaus Database

You are currently viewing the URLhaus database entry for http://elm.kg/wp-admin/sZnZSz3iN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2036189
URL: http://elm.kg/wp-admin/sZnZSz3iN/
URL Status:Offline
Host: elm.kg
Date added:2022-02-08 06:52:17 UTC
Last online:2022-02-10 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 06:53:17 UTC to adm{at}infotel[dot]kg)
Takedown time:2 days, 0 hours, 6 minutes Poor (down since 2022-02-10 06:59:45 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09y0CDkJfq.dlldll 18e3b0d902f95fb74affd0f0e203b5a7d6d8a9aa17967611b17377008b5f0c52Virustotal results 1.52%Heodo
2022-02-099ZXogULn2edjNjOKqAVamFQ.dlldll 3f270a045c7790d873722c023a6102dc78996d20f12190f3dccade2643af0231n/a Heodo
2022-02-090SsYlEtTzjulleJF3.dlldll d16a46d52404ed920308e2adc7f1e19e6a6f6bd6a2147a558a925feea4c44fdcVirustotal results 47.76% Heodo
2022-02-09x9DuGGlbH6kfK3CI7YsRP.dlldll e1a7c1684742856232d67998247448648427be9da0ba8a2d3f2b4701b2d0a5f4n/a Heodo
2022-02-09g9fSP7RyRTbl.dlldll 660f99f56e79ad2133653eb5708f03f1134ab1543b7d137018e1bf4697671a81Virustotal results 38.24% Heodo
2022-02-090vSQdipzR53i6oI07.dlldll e57bcb918529896e2a1843d2a0dfc28778806959555fef935eeddc103b060b98n/a Heodo
2022-02-09DydT1SVGn.dlldll d6bf53179ebacf00bc89a181a886275170795d6bb96f7a0273f1c3ede036d726Virustotal results 29.41% Heodo
2022-02-09WRqExnAeCMCGA8AhjAvJjQjlMHCP.dlldll dff2d695842cb4989b00b70e555b99f38a7e531f64d604737b37c2ec9a6fad0cVirustotal results 29.41% Heodo
2022-02-09GCm6VsNwi134Vn1vES5HNJzOmXDmKHh0.dlldll 9cb3b0cda875b1c6cf6ab93d533488de9c7fbc13776ff986f0d5a9bcffb78c96n/a Heodo
2022-02-09z3zF3hHTxJxyxiGS0cq2xNTHS.dlldll 6aef4ec242aed3271c09152bdb4e3797e8a7b4d0ad32680904cf544d2f24aafcVirustotal results 29.41%Heodo
2022-02-099RzHaM5wi2t4efQpv1ff9zbApG.dlldll ed45011f39129ef959ee0cbd72bf2e8b913e4420c7b4e18ef1d8121699834c14n/a Heodo
2022-02-08pHNFd3CU3IRK1mD4qi1iGOy5R6RQbG8.dlldll 9cd7c3b2804a3d0524303df68409294a332eb5339e9c8f71c5fc91631a629002n/a Heodo
2022-02-08eSFa3zdN6aXF1A1g.dlldll 68d1f684aa1b57ddb60c8a275e89782eba308716ad0578bdcb561e4b30aff997n/a Heodo
2022-02-08uss7pCYyI1ZLzMXO1socxzP.dlldll a071b4d764785231dace1db4c0c6941c53cc178ab7b9b03e680e9b95851b64e9n/a Heodo
2022-02-08Evu2vjQ.dlldll f838cd9069942773d20e57004a55c26dc54d5ac1f89a694780c07caacfa9a534n/a Heodo
2022-02-087C455T2C.dlldll b5a505804fb8b25ac27e6406e17140095160bf6b472ed481e99595b57c1985ban/a Heodo
2022-02-085oP4OOoZlrsyB5s0liOZvWJ1.dlldll 0849f1fce358b303840936940c88aaee176313791757c85e3a2458e75d7afd6cn/a Heodo
2022-02-08bjU9BnqJcXKIXDiShtzlcg9CSjPffaZAF.dlldll 62b0091f773826721732471f776cd1f5337845d126612ab94f0e834b198c1cc5n/a Heodo
2022-02-085JeHkUMT4ChXLKZcSEyoU1bvqPAhM.dlldll a133dcbdd7df2adfc05bee852cb4fdc9c86ac2c9ad8fc0fd57743b9f859bdd89n/a Heodo
2022-02-08svreSmkZ3ZTriY8nF8U2MG0FZ.dlldll 80089e2da67b114ae315ed3d57eec7b9848bed06d66607fb2a14988f429f757dn/a Heodo
2022-02-08bLNKKHo6FXB9JOSKYSuhIpAf2.dlldll fc20b922e2c640a8c515f38c07c81a04a72f15c8d874801ae2577c487bda5ac1n/a Heodo
2022-02-08z77z22m4g1M.dlldll 2ce98f23620bfdf74566dce33a877f27269ea06a3662b425461e1bb85ee67400Virustotal results 20.90% Heodo
2022-02-08pkIkivOPwJ2Lt7j0ymAVrhO9wCtW89YNQ.dlldll 63aff8208ea9ac90946bcec73357cbb0a78b46bcb368711c415bb67e4233053fn/a Heodo
2022-02-08LV2X9hUlzCjShcL51nZ.dlldll c5c8dbaa7a3db9c5487eae6ccd40861bfbc1cec16c47cd4e6b9a092b89a8cf4an/a Heodo
2022-02-08Brs4VawmetlqSKHWUfyJmBbFOl.dlldll e8e43e0523dd1049ca24a9132f94401dd7722abb5a456b2c946ec84d3b5719b7n/a Heodo
2022-02-08uAw6e.dlldll 1c1399d5c2173fd30da9125c7d65fdb49bf7c06a877321ea2646244e40af7c06n/a Heodo
2022-02-08oqHUPIoGa5hVUUooGsb0xOebIJB.dlldll 2e231d4ccb5de07811583fb4dc09ce078d127ecae0823d0050600b90d0e250e5n/a Heodo
2022-02-08x2qFzEFQ.dlldll c92dc4b2c9f4cb557250b1e5e58223d746d99b04954804cc3adf3982cc82a4ben/a Heodo
2022-02-08blIPNly4JHa.dlldll cd455aa422f4543ebf743838651c0a6f39ffb2970722bf450effd2325a21100cn/a Heodo
2022-02-08GErOk7uGUZ8YB82u1Xll.dlldll 853f1f1b3b3eff240e3357334314d61ee1834aab94a1920ad95830a4a6c1360an/a Heodo