URLhaus Database

You are currently viewing the URLhaus database entry for http://ronfrankproductions.com/4agreements/trEgS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2036347
URL: http://ronfrankproductions.com/4agreements/trEgS/
URL Status:Offline
Host: ronfrankproductions.com
Date added:2022-02-08 08:32:12 UTC
Last online:2022-02-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 08:33:15 UTC to dns{at}aplus[dot]net)
Takedown time:6 days, 7 hours, 47 minutes Bad (down since 2022-02-14 16:20:49 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09BPwcTu.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84n/aHeodo
2022-02-09saCIReuv8T9o.dlldll 4d26814823d3a70492d1b858ce2541b6e6afcd48d1e72887b300ca62c0ebb9d8n/a Heodo
2022-02-09vyGTlfBOVmmUs.dlldll b671abbb2336e1611cf0de1a394aa8fc8f05b0b48f629d2c9cfb511a252e5063n/a Heodo
2022-02-09oqjuyW2fkd.dlldll f8cf7af7501d03e7a7d2bad9e8263436b0de68a16a9693f3debe23496f5fbfd7n/a Heodo
2022-02-09mjl4Z3X.dlldll 504dc7903c44c91922e492458b736cf723ca213454e084c9ea12782a803cccc7n/a Heodo
2022-02-09hGwDCTNSTTHsi.dlldll 66faade3afd1d168e236d30db6045649b90393eb72c31a30e136a5448ded69a6n/a Heodo
2022-02-09nooiz0.dlldll f7f47b213329ef13c11bbfc0e368898b757b512323d020ed1e725d65079782f9Virustotal results 20.90% Heodo
2022-02-08GK7tc.dlldll 505ca5a2e76920b64f054d976866a0026a6d645ebe89b1fc737019e88a117cd1n/a Heodo
2022-02-08syJGr.dlldll 03ddaa01aa9dbae08c9cc2fd8e94bbec8c45a448478b748a3c3278047ccfda57Virustotal results 20.75% Heodo
2022-02-08jzUkEyq.dlldll e5335e568ec1bf823ec1c803a9e96255eb096cd49ace8aa031087b1b76fd1361Virustotal results 20.90% Heodo
2022-02-08ToiRYH1U2Zrn.dlldll aa88f378563746c73756b1784f6f38623baccf62c30b578dde8236c225823130n/a Heodo
2022-02-08aqRGqsjDa7umokx3KAJ.dlldll a11ce07896a54ccbe39b6673f32b980fc293a3add645a1502fa47a4cefe04234n/a Heodo
2022-02-08SRYFPq65R9uQ.dlldll 9cc508ed315b58c74f604b618f98983989139530c4bc184d0adec8bedf3842fcn/a Heodo
2022-02-08Gz5A3GH0PNYH0Gc.dlldll 4f1b2751fcf39b1cbff7832500a04e9a193e8c45062e34d6071b0d0e8663cfd8n/a Heodo
2022-02-08mggzri.dlldll 3373d9546a8f84b47ddd17f1bd6bd3795dd3f23710d5a6ebd7186e0c905b9acbn/a Heodo
2022-02-086pnK4GIKxQ.dlldll 88e59c505f3d16174a6cee48fc35638063263728abd8c7961c257efa9016914dVirustotal results 19.12% Heodo
2022-02-08LhXZEh5.dlldll 262257828e2cbeced26362325d50966633c6f896c8e6af76af8b33950c2f2bb8n/a Heodo
2022-02-08iqlbEpFb.dlldll aa4d2d0d5141221a4197a566b443576ae900f6cde393e5aa3dddf3a4b024cbecVirustotal results 14.71% Heodo
2022-02-08E22wlk1yER.dlldll f72649da2aa92b68c13713d5391e750790cc851161d3c8a3082e6825d293219bn/a Heodo
2022-02-08jE9ba0VOyDDMp.dlldll 6e3222b8b3da6bad2fe063f0afd5aa964f08dcc37985c1c08f6029c30130420bn/a Heodo
2022-02-08psQbAjrrEOXWPrS.dlldll 18e28de838f7f7822e3668dbbbde4daf9b54a28a02063beac586ad6f5fd66036n/a Heodo
2022-02-08RDOSAzJikECHQ.dlldll f9c5fb058a917481c1d7c576e6b72f7d59bf440936baf0987d41726110003949n/a Heodo
2022-02-08eiBLuBL8nN5zO.dlldll ebe352641754458555f1444a3ecd682d84ef54a199d2af52de7bd28963684c04n/a Heodo