URLhaus Database

You are currently viewing the URLhaus database entry for http://rosewoodcraft.com/Merchant2/5.00/PGqX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2036896
URL: http://rosewoodcraft.com/Merchant2/5.00/PGqX/
URL Status:Offline
Host: rosewoodcraft.com
Date added:2022-02-08 14:20:13 UTC
Last online:2022-02-16 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-08 14:21:21 UTC to dns{at}aplus[dot]net)
Takedown time:7 days, 10 hours, 33 minutes Bad (down since 2022-02-16 00:54:34 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-09a6Bz66Y3Bl8.dlldll 18e3b0d902f95fb74affd0f0e203b5a7d6d8a9aa17967611b17377008b5f0c52Virustotal results 13.43%Heodo
2022-02-09ktNQp92Ne4T3IHUOT7Wy701Dk4w3OPnF.dlldll a7c6abbc3241b6cfcfa27158e80bd50d3c9f1ae97e86481ccabd5b2337670690n/a Heodo
2022-02-08XZ2MNPqIpbSmy37ix6NKr8pFKNZQdoP.dlldll bc4cd26a1bb23f2b0b390e42a4f4a7b3f268299b3d40f6aabb2f12b5e1ed6071Virustotal results 26.09% Heodo
2022-02-08PGhOdhz.dlldll ca371ed209d12635225a72a95df0e7250cc3401bb17bac65ac3c6cdcb984cafbn/a Heodo
2022-02-08JxjU2fcbwrq6YKyz3RzTiBDnqQIb8zkA.dlldll bab83f0cddded4c86e3977066cd8983f4392ac5143f96a235f3bf2560c1a516bn/a Heodo
2022-02-08ml1pEzm.dlldll 6fd5c92e5157a8654938aaa4ac8a9340dbd0e49b9d22dde6329bbfb0810a85f5n/a Heodo
2022-02-08Vz1jIYLds9.dlldll bf021848f267018ea23e389d40c64215a8bca59e7cc2f3537245b3145441deb2n/a Heodo
2022-02-089vxxAmOwRVFIDarneRsW3Mm.dlldll 6f5af39f2da0bb3abf450d29ff8fb21e37c438117ce0405fb9c268866f6d1c6dn/a Heodo
2022-02-08xtP8pBEGhGWM42UZCHGcAA.dlldll 138935f1f8940e7b3f320445a1fd4818166a561c19de329895928a4dd6ff2493n/a Heodo
2022-02-084sIzKI6bAa2m4rDK1ck.dlldll 8c073fa33fb74b780f7fe4aab807d8393cc6160fb4b5d6bce14ff1054460b184n/a Heodo
2022-02-08phpTV6Tcqkp9eKjpYImmDOr7qIqR.dlldll 2bbded7445983e533fe2c4e40760124596042536b34f86fd5f95a8d361355ccdn/a Heodo
2022-02-08oVZlfwHcCGtLwmuDi.dlldll ccf68c037c2ab52b636bf68266a2b1117b850e61d379c58173ed062936ea64fdn/a Heodo