URLhaus Database

You are currently viewing the URLhaus database entry for http://k7tgu.com/Bryce/UBfCU05bih/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2036352
URL: http://k7tgu.com/Bryce/UBfCU05bih/
URL Status:Offline
Host: k7tgu.com
Date added:2022-02-08 08:32:13 UTC
Last online:2022-02-27 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 08:33:15 UTC to dns{at}aplus[dot]net)
Takedown time:19 days, 13 hours, 20 minutes Bad (down since 2022-02-27 21:53:26 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09UGSkaePL35JQHHBGT9m.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 10.61%Heodo
2022-02-09UR4PSSO.dlldll 942745e84eeabc35a7ceae9818df56ed23801b6ff7fb111e142ad5cbce58a969n/a Heodo
2022-02-09tL4d8M.dlldll a3a668b89b180f12880bf33a80847a4a463108ca879b101fbb5e3f3738349c76Virustotal results 25.00% Heodo
2022-02-09w3ycEGI757.dlldll 76efcd1ed4fe1fd483e815a531fbaf6b9d64add1d82834e1623b607110f8da8fVirustotal results 24.24% Heodo
2022-02-09PTfq7ZR7gjz3vqUu.dlldll 669982793add51b72344ef118be8b468546d6835c832f13286d1a8d23b1954cbVirustotal results 22.39% Heodo
2022-02-09JhgldiJr6j0X.dlldll 65be44be169fee9c4dd9772b1852772d8a32285890338d657157792084c27246Virustotal results 19.40% Heodo
2022-02-08QpZ.dlldll 4ddc1a81b3f7acf8f04d77781af2a754652f4a18883d1f190a78a28453ebadbfn/a Heodo
2022-02-08nEDyr.dlldll 2e75131c13d316e5bc645b2142b9eb5308f147f7b3ac000856b87a02f42646fan/a Heodo
2022-02-08vxrPdUmMaWFqIdnjy.dlldll 7db236785789f0085d53b385656a81292f059da9236638d0bdfdf9171788f488n/a Heodo
2022-02-08n2SBPB9Qo4JUSXS86Y.dlldll c7b323aaba530eefc18cd60be13a34844502a9425afd225b9745faa2a5362594n/a Heodo
2022-02-08ufl5jX.dlldll 5b029ea2e91ed17e27620893b5c7b16f898b6666c0762dd2c4fdfb7225beeb29n/a Heodo
2022-02-08WCLhDhO.dlldll 5e13c585ccfbc5a0288a7df743b84bb59743b3acd9334f67f7f84035bd681bb5Virustotal results 21.54%Heodo
2022-02-08pPHdfD0jfs.dlldll a118358647af6d3e7e6689f2f8a313e2b0ba966678b4f101f2e06b786e4d6effn/a Heodo
2022-02-084Mf9SHo90g5JOJBNyn8.dlldll 63eb33782aa04610353e490dff4ea5ac66731ec214bc38eaf30f628943d735f1n/a Heodo
2022-02-08wPpbV5Q.dlldll c46015ab915cece7e855ff819f11e3a5fadf44582eb26d0ac9eb06c550023743n/a Heodo
2022-02-08BixT3ZUmdSfyH.dlldll 966127f66bafafc4a94db76568443195681735b454f5d9adc5329c7492ab1bden/a Heodo
2022-02-08msLTSpNH9g7RUe1u2a.dlldll 78cb54c94f51fc89d13056c2bad680f5793bd4970f3f3755b39ac792959d6a2aVirustotal results 19.12% Heodo
2022-02-08KTr.dlldll 5b93037246046b953a591d2c130ebf9e77d909022f637a8c09f208a96b80791bn/a Heodo
2022-02-08xKhbKMyMEVt.dlldll 4fff16c05c791608509f3bcae4e178ce0b9de9126daae9440acadeed27528bb8n/a Heodo
2022-02-08WOofZ0m.dlldll 19846c2d71d813c39ffad9160e0515757230787f0a2a745db1dba31b5ac42219n/a Heodo
2022-02-08xvELahdlDg.dlldll be90776d4bb622723b0bd816d79a5dacdbe400e049b3e66fe825d3506c50b182n/a Heodo
2022-02-08NpSuev6w1zf8aJZWJ.dlldll adc1c08ed6201b5f4d2f4057be1721e170e941656019e20f7a224340e17a74bfn/a Heodo
2022-02-08Ec0lu.dlldll d60a518f4e6280a19e94221c15803a0ab02cd07e8242b2a55fe8cec5ce4c2263n/a Heodo
2022-02-08qcBJONBGj25.dlldll e575ff32b0a329c8ee9ad4b671db62c240030f2c7d3e2bf2048b1234045cafben/a Heodo